VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-47871High· 8.8
2mo ago

VMware Avi Load Balancer contains a directory traversal vulnerability

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1…

▾ TwilightEPSS 0.96%via NVD
CVE-2026-62229High· 8.8
2mo ago

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the a…

▾ TwilightEPSS 0.72%via NVD
GHSA-mfr4-mq8w-vmg6Medium· 6.6
2mo ago

PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs

PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs

▾ Sunlitproot-distro · proot-distrovia GHSA
CVE-2026-53598High· 7.5
2mo ago

Prompty: Arbitrary file read via file reference expansion

Prompty: Arbitrary file read via file reference expansion

▾ Twilightprompty · promptyEPSS 1.3%via GHSA
CVE-2026-45576High· 7.5
2mo ago

zrok is software for sharing web services, files, and network resources

zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to Files…

▾ Twilightnetfoundry · zrokEPSS 0.50%via NVD
CVE-2026-45568Critical· 9.1
2mo ago

zrok is software for sharing web services, files, and network resources

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the reque…

▾ Midnightnetfoundry · zrokEPSS 0.54%via NVD
CVE-2026-46336High· 7.1
2mo ago

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated users can rename uploaded files with path traversal sequences b…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-20146Medium· 5.5
2mo ago

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read …

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read …

▾ Sunlitcisco · identity_services_engine_passive_identity_connectorEPSS 0.50%via NVD
CVE-2026-45419None
2mo ago

DataEase is an open source data visualization and analysis tool

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker…

▾ SunlitEPSS 0.46%via NVD
GHSA-62gx-5q78-wrvxHigh· 8.8
2mo ago

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

▾ Twilightobsidian-local-rest-api · obsidian-local-rest-apivia GHSA
CVE-2026-9108High· 7.5
2mo ago

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during …

▾ Twilightrockwellautomation · studio_5000_logix_designerEPSS 0.18%via NVD
CVE-2026-15265Critical· 9.1
2mo ago

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

▾ Midnighttenable · nessus_agentEPSS 0.56%via NVD
CVE-2026-48310High· 8.6
2mo ago

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access…

▾ Twilightadobe · experience_managerEPSS 1.0%via NVD
CVE-2026-45496Medium· 5.5
2mo ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

▾ Sunlitmicrosoft · visual_studio_codeEPSS 0.47%via NVD
CVE-2026-60114High· 7.5
2mo ago

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup fi…

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup fi…

▾ Twilightdan-in-ca · sustainable_irrigation_platformEPSS 0.50%via NVD
GHSA-hgjx-r89m-m7v4Critical· 9.9
2mo ago

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-54250Medium· 5.8
2mo ago

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.17%via GHSA
CVE-2026-45693High· 7.5
2mo ago

FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

▾ Twilightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-54065High· 8.7
2mo ago

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-13014None
2mo ago

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, c…

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, c…

▾ SunlitEPSS 0.70%via NVD
CVE-2026-15527Medium· 5.3
2mo ago

A vulnerability has been found in better-auth better-icons up to 1.0.5

A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/sync_icon. Such manipulation of the argument icons_file leads to path traversal. An attac…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-15526Low· 3.3
2mo ago

A flaw has been found in augmnt augments-mcp-server 7.1.0

A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component scan_project_deps. Executing a manipulation of the argument package…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-15524Low· 3.3
2mo ago

A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1

A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Such manipulation of the argument projectName leads to path travers…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-15522Medium· 5.3
2mo ago

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath res…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-15521Medium· 5.3
2mo ago

A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0

A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation of the argument filePath leads to path tr…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-56260Critical· 9.1
2mo ago

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supp…

▾ Midnightcrawl4ai · crawl4aiEPSS 0.65%via NVD
CVE-2026-61445Critical· 9.9
2mo ago

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts throug…

▾ MidnightEPSS 0.88%via NVD
CVE-2026-60088Medium· 5.5
2mo ago

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute pa…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-9282High· 7.5PoC
2mo ago

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrar…

▾ MidnightEPSS 2.9%via NVD
CVE-2026-11426Medium· 6.5
2mo ago

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and co…

▾ SunlitEPSS 0.46%via NVD
CWE-22 vulnerabilities (CVEs) — page 24 · VulnSea