VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-54468Medium· 6.5
2mo ago

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.

▾ Sunlitdell · unisphere_for_powermaxEPSS 0.45%via NVD
CVE-2026-55852None
2mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 …

▾ SunlitEPSS 0.68%via NVD
CVE-2026-42219None
2mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.

▾ SunlitEPSS 0.68%via NVD
CVE-2026-41482None
2mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.

▾ SunlitEPSS 0.50%via NVD
CVE-2026-58499High· 8.2
2mo ago

EverOS is a memory runtime for agents

EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint because the per-message sender_id field was not validated as a path-safe identifier, unlike a…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-55469Medium· 6.5
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deleti…

▾ SunlitEPSS 0.59%via NVD
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
GHSA-qv4m-m73m-8hj7High· 8.8
2mo ago

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

▾ Twilightnotrinos · notrinos/notrinos-erpvia GHSA
GHSA-wm45-qh3g-v83fHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary server-side file read via attachment upload

mcp-atlassian: Arbitrary server-side file read via attachment upload

▾ Twilightmcp-atlassian · mcp-atlassianvia OSV
GHSA-g5r6-gv6m-f5jvHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

▾ Twilightmcp-atlassian · mcp-atlassianvia GHSA
CVE-2026-47826Critical· 9.1
2mo ago

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

▾ Midnightcloudfoundry · bosh_cliEPSS 0.55%via NVD
CVE-2026-39245Medium· 6.2
2mo ago

decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write

decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.…

▾ Sunlitdecompress_project · decompressEPSS 0.38%via NVD
GHSA-52vm-mxx8-f227High· 7.7
2mo ago

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

▾ Twilightphantom-audio · phantom-audiovia GHSA
GHSA-c43v-4cr8-6mvpLow
2mo ago

Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read

Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-55874High· 7.7
2mo ago

SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874)

A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user,…

▾ TwilightRed Hat · Cryostat 4 on RHEL 9EPSS 0.61%via CSAF
CVE-2026-59820Medium· 6.5
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authen…

▾ Sunlitlitellm · litellmEPSS 0.59%via NVD
CVE-2026-27823Critical
2mo ago

EGroupware has a Remote Code Execution Vulnerability

EGroupware has a Remote Code Execution Vulnerability

▾ Midnightegroupware · egroupware/egroupwareEPSS 0.97%via GHSA
CVE-2026-35363Medium· 5.6
2mo ago

rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection

rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection

▾ Sunlituu_rm · uu_rmEPSS 0.17%via GHSA
CVE-2026-53486Critical· 9.1
2mo ago

Decompress: Archive extraction can create files and links outside of the target directory

Decompress: Archive extraction can create files and links outside of the target directory

▾ Midnightxhmikosr · @xhmikosr/decompressEPSS 0.75%via GHSA
CVE-2026-54760Critical
2mo ago

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

▾ Midnightlangroid · langroidEPSS 0.65%via GHSA
CVE-2026-35338High· 7.3
2mo ago

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

▾ Twilightuu_chmod · uu_chmodEPSS 0.20%via GHSA
CVE-2026-14628Medium· 5.3PoC
2mo ago

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path tr…

▾ TwilightEPSS 0.77%via NVD
CVE-2026-28705None
2mo ago

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

▾ SunlitEPSS 0.45%via NVD
CVE-2026-41124Low· 2.3
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limi…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limi…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-47896None
2mo ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta0…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta0…

▾ SunlitEPSS 0.81%via NVD
CVE-2026-47897None
2mo ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00…

▾ SunlitEPSS 0.72%via NVD
CVE-2026-9725Critical· 9.1
2mo ago

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() func…

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() func…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-14352High· 7.5
2mo ago

The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter

The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of …

▾ TwilightEPSS 0.68%via NVD
CVE-2026-9559Critical· 9.9
2mo ago

Mautic vulnerable to Path Traversal via Campaign Import

Mautic vulnerable to Path Traversal via Campaign Import

▾ Midnightmautic · mautic/coreEPSS 0.93%via GHSA
GHSA-322x-v876-g883High
2mo ago

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

▾ Twilightasymmetric-effort · @asymmetric-effort/nogginlessdomvia GHSA
CWE-22 vulnerabilities (CVEs) — page 25 · VulnSea