VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-52830Critical· 9.4
2mo ago

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

▾ Midnightfast-mcp-telegram · fast-mcp-telegramEPSS 0.65%via GHSA
CVE-2026-50180High
2mo ago

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

▾ Twilightlangroid · langroidEPSS 0.69%via GHSA
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

▾ Midnightlangroid · langroidEPSS 0.18%via GHSA
CVE-2026-20191High· 7.5
2mo ago

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attack…

▾ Twilightcisco · catalyst_centerEPSS 0.65%via NVD
CVE-2026-50162Medium· 5.3
2mo ago

oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)

A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…

▾ SunlitRed Hat · Red Hat Edge Manager 1.1EPSS 0.51%via CSAF
CVE-2026-50163High· 7.1
2mo ago

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

▾ Twilightoras-go · oras.land/oras-go/v2EPSS 0.43%via GHSA
GHSA-j6hm-v3x2-qv6jLow
2mo ago

land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory

land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory

▾ Sunlitoras · land.oras:oras-java-sdkvia GHSA
GHSA-2wwr-9x6f-88gpMedium· 5.3
2mo ago

EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components

EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components

▾ Sunliteasycorp · easycorp/easyadmin-bundlevia GHSA
CVE-2026-12243High· 7.5PoC
2mo ago

nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)

A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4via CSAF
CVE-2026-58015Medium· 5.9
2mo ago

A flaw was found in GLib

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_co…

▾ Sunlitgnome · glibEPSS 0.91%via NVD
CVE-2026-57079Medium· 5.3
2mo ago

Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path

Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and m…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-8023High· 7.5PoC
3mo ago

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both …

▾ Midnightzephyrproject · zephyrEPSS 0.87%via NVD
CVE-2026-13528High· 7.3
3mo ago

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/…

▾ TwilightEPSS 0.65%via NVD
CVE-2026-13509Medium· 6.3
3mo ago

A vulnerability has been found in RAGapp up to 0.1.5

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Knowledge File Handler. Such manipulation…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-13503Medium· 5.3
3mo ago

A vulnerability was detected in antlr ANTLR4 up to 4.13.2

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The …

▾ SunlitEPSS 0.77%via NVD
GHSA-fr4h-3cph-29xvHigh· 7.1
3mo ago

pnpm: Hoisted install imports lockfile alias outside node_modules

pnpm: Hoisted install imports lockfile alias outside node_modules

▾ Twilightpnpm · pnpmvia GHSA
GHSA-72r4-9c5j-mj57High· 7.1
3mo ago

pnpm: `patch-remove` could delete project-selected files outside the patches directory

pnpm: `patch-remove` could delete project-selected files outside the patches directory

▾ Twilightpnpm · pnpmvia GHSA
GHSA-qrv3-253h-g69cHigh· 8.2
3mo ago

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

▾ Twilightpnpm · pnpmvia GHSA
CVE-2026-55677High· 7.5
3mo ago

github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)

A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encod…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.9.2)EPSS 0.43%via CSAF
CVE-2026-49991High· 8.6
3mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write…

▾ TwilightEPSS 0.41%via NVD
GHSA-3p34-w4f6-5xh2High· 7.5
3mo ago

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

▾ Twilightbetter-helperjs · better-helperjsvia GHSA
CVE-2026-48820Medium
3mo ago

CakePHP: View::element() is missing a path containment check

CakePHP: View::element() is missing a path containment check

▾ Sunlitcakephp · cakephp/cakephpEPSS 0.37%via GHSA
GHSA-rp72-5v5q-2446Low
3mo ago

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

▾ Sunlitcardano402 · @cardano402/mcp-servervia GHSA
CVE-2026-49342Medium· 5.3
3mo ago

YARD static cache reads raw traversal paths before router sanitization

YARD static cache reads raw traversal paths before router sanitization

▾ Sunlityard · yardEPSS 0.40%via GHSA
CVE-2026-50015High· 7.3
3mo ago

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

▾ Twilightpnpm · pnpmEPSS 0.43%via GHSA
CVE-2026-53519Critical· 9.1PoC
3mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

▾ Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 2.3%via GHSA
CVE-2026-49340High· 8.1
3mo ago

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.43%via GHSA
CVE-2026-49339High· 7.1
3mo ago

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.39%via GHSA
CVE-2026-55699Medium· 6.5
3mo ago

pnpm: Reserved bin name deletes PNPM_HOME during global remove

pnpm: Reserved bin name deletes PNPM_HOME during global remove

▾ Sunlitpnpm · pnpmEPSS 0.45%via GHSA
CVE-2026-55700High· 7.1
3mo ago

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

▾ Twilightpnpm · pnpmEPSS 0.42%via GHSA
CWE-22 vulnerabilities (CVEs) — page 26 · VulnSea