VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-13339High· 7.5
1mo ago

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the conte…

▾ TwilightEPSS 0.94%via NVD
CVE-2026-67309High· 7.5
1mo ago

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation)

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingre…

▾ Twilighttraefik · traefikEPSS 0.66%via NVD
CVE-2026-67295Medium· 6.3
1mo ago

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and …

▾ SunlitEPSS 0.36%via NVD
CVE-2026-15601Medium· 4.9
1mo ago

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for au…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-15450High· 8.1
1mo ago

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path f…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-15006High· 7.5
1mo ago

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This ma…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-62999High· 7.5PoC
1mo ago

Copier is a library and CLI app for rendering project templates

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an…

▾ Midnightcopier-org · copierEPSS 0.44%via NVD
CVE-2026-56673High· 7.5
1mo ago

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directo…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-63222High· 7.5
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to w…

▾ Twilightcodeigniter4 · codeigniter4/frameworkEPSS 0.64%via NVD
CVE-2026-55825Low· 3.1
1mo ago

Contao is an Open Source CMS

Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file fr…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-56671High· 7.5
1mo ago

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a conta…

▾ TwilightEPSS 0.97%via NVD
CVE-2026-54785Medium· 6.2
1mo ago

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining…

▾ Sunlitgemini-bridge · gemini-bridgeEPSS 0.19%via NVD
CVE-2016-1000305Medium
1mo ago

guard-livereload has a directory traversal vulnerability

guard-livereload has a directory traversal vulnerability

▾ Sunlitguard-livereload · guard-livereloadvia GHSA
CVE-2026-54910High· 7.7
1mo ago

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

▾ Twilightgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.46%via GHSA
CVE-2026-53502High
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or f…

▾ Twilightthumbor · thumborEPSS 0.52%via NVD
CVE-2026-12074High· 7.5
1mo ago

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nlt…

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

▾ Twilightnltk · nltkvia OSV
CVE-2026-12072High· 7.5
1mo ago

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (E…

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

▾ Twilightnltk · nltkvia OSV
CVE-2026-55495Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape th…

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.38%via NVD
CVE-2026-59310Critical· 9.8CISA KEVPoC
1mo ago

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

▾ HadalVMware · Cloud FoundationEPSS 2.6%via CVEORG
CVE-2026-6540High· 7.5
1mo ago

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes …

▾ Twilighttigera · calicoEPSS 0.54%via NVD
CVE-2026-67429Critical· 10.0
1mo ago

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

▾ Midnightflyto-core · flyto-coreEPSS 0.77%via GHSA
GHSA-pmwx-rm49-xv39Low
2mo ago

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

▾ Sunlitactiverecord-tenanted · activerecord-tenantedvia GHSA
CVE-2026-50558Medium· 5.9
2mo ago

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote…

▾ Sunlitpenelope-shell-handler · penelope-shell-handlerEPSS 0.37%via NVD
CVE-2026-55389High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.55%via OSV
CVE-2026-66063Medium· 6.5
2mo ago

goshs has a Path Traversal issue

goshs has a Path Traversal issue

▾ Sunlitgoshs · goshs.de/goshs/v2EPSS 0.34%via GHSA
CVE-2026-54650High· 8.6
2mo ago

openhole exposes localhost to the internet in one command

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing…

▾ Twilightbablilayoub · github.com/bablilayoub/openholeEPSS 0.53%via NVD
CVE-2026-54659Medium
2mo ago

Pagy I18n locale option is not validated before being used in a file path

Pagy I18n locale option is not validated before being used in a file path

▾ Sunlitpagy · pagyEPSS 0.54%via GHSA
CVE-2026-66064Medium· 5.3
2mo ago

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

▾ Sunlitpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.45%via GHSA
CVE-2026-55390High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.53%via GHSA
CVE-2026-50567High· 7.7
2mo ago

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

▾ Twilightfission · github.com/fission/fissionEPSS 0.45%via GHSA
CWE-22 vulnerabilities (CVEs) — page 22 · VulnSea