VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-44024Critical· 9.8PoC
3mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-48944Medium· 6.5
3mo ago

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. A…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-48776Medium· 4.2
3mo ago

LangGraph SDK has unsafe URL path construction

LangGraph SDK has unsafe URL path construction

▾ Sunlitlanggraph-sdk · langgraph-sdkEPSS 0.29%via GHSA
CVE-2026-49219Medium· 5.5
3mo ago

ImageMagick: Policy Bypass can read disallowed files via symlink

ImageMagick: Policy Bypass can read disallowed files via symlink

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.17%via GHSA
CVE-2026-57296High· 8.8
3mo ago

Jenkins External Workspace Manager Plugin has a path traversal vulnerability

Jenkins External Workspace Manager Plugin has a path traversal vulnerability

▾ Twilightjenkins-ci · org.jenkins-ci.plugins:external-workspace-managerEPSS 0.83%via GHSA
CVE-2026-11940High· 7.3
3mo ago

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's…

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via NVD
CVE-2026-52811Critical
3mo ago

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym

▾ Midnightgogs · gogs.io/gogsEPSS 0.47%via GHSA
CVE-2026-53925High· 7.8
3mo ago

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

▾ Twilightglances · glancesEPSS 0.18%via GHSA
CVE-2026-54557Medium· 5.5
3mo ago

mise HTTP backend uses raw version path for install symlink destination

mise HTTP backend uses raw version path for install symlink destination

▾ Sunlitmise · miseEPSS 0.17%via GHSA
CVE-2026-55488High
3mo ago

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

▾ Twilightmotioneye · motioneyeEPSS 0.62%via GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
CVE-2026-48126High· 8.2
3mo ago

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

▾ Twilightxyproto · github.com/xyproto/algernonEPSS 0.50%via GHSA
CVE-2026-53779High· 7.5
3mo ago

WebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on Windows

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) tha…

▾ Twilightwebp-sh · webp_server_goEPSS 0.59%via CVEORG
CVE-2026-42129High· 7.7
3mo ago

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

▾ Twilightgrafana · loki_datasourceEPSS 0.44%via NVD
CVE-2026-10601Medium· 5.4
3mo ago

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…

▾ Sunlitgrafana · grafanaEPSS 0.29%via NVD
CVE-2026-54293High· 7.5PoC
3mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path tr…

▾ Midnightnltk · nltkEPSS 0.63%via NVD
CVE-2026-31978Medium· 6.5
3mo ago

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

▾ Sunlitmotioneye · motioneyeEPSS 0.42%via GHSA
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

▾ Twilightskillctl · skillctlvia GHSA
CVE-2026-54352Critical· 9.6
3mo ago

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

▾ Midnightbudibase · @budibase/serverEPSS 0.49%via GHSA
CVE-2026-54414Critical· 9.8
3mo ago

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by F…

▾ MidnightEPSS 0.66%via NVD
GHSA-fwh2-95jw-g4j6High· 8.8
3mo ago

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-2h46-9x5w-4wf7Medium
3mo ago

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

▾ Sunlitentireio · github.com/entireio/clivia GHSA
CVE-2026-11769Medium
3mo ago

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

▾ Sunlitgrafana · github.com/grafana/grafana-operator/v5EPSS 0.36%via GHSA
CVE-2026-55878High· 7.8
3mo ago

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

▾ Twilightsymfony · symfony/ux-toolkitEPSS 0.19%via GHSA
GHSA-9c83-rr99-vfwjMedium
3mo ago

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

▾ Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
GHSA-2fmp-9rvw-hc96High· 7.1
3mo ago

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

▾ Twilightnetwork-ai · network-aivia GHSA
GHSA-jvcm-f35g-w78pMedium· 6.5
3mo ago

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-6x2m-p4xp-wg22Medium· 5.5
3mo ago

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-48x2-6pr9-2jjfMedium· 6.1
3mo ago

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-c795-2g9c-j48mHigh· 8.2
3mo ago

EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id

EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id

▾ Twilighteveros · everosvia GHSA
CWE-22 vulnerabilities (CVEs) — page 27 · VulnSea