VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-56266Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.48%via GHSA
GHSA-7cx2-g3h9-382pHigh· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

▾ Twilightcrawl4ai · crawl4aivia GHSA
CVE-2026-52844High· 7.5
3mo ago

Caddy: Windows `file_server` path authorization bypass via encoded backslash

Caddy: Windows `file_server` path authorization bypass via encoded backslash

▾ Twilightcaddyserver · github.com/caddyserver/caddy/v2EPSS 0.62%via GHSA
CVE-2026-52797High· 8.5
3mo ago

Gogs: Overwriting critical files results in a denial of service

Gogs: Overwriting critical files results in a denial of service

▾ Twilightgogs · gogs.io/gogsEPSS 0.53%via GHSA
CVE-2026-49982High· 8.2
3mo ago

tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template

tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template

▾ Twilighttmp · tmpEPSS 0.60%via GHSA
CVE-2026-49356Low· 3.2
3mo ago

@babel/core: Arbitrary File Read via sourceMappingURL Comment

@babel/core: Arbitrary File Read via sourceMappingURL Comment

▾ Sunlitbabel · @babel/coreEPSS 0.15%via GHSA
CVE-2026-53571HighPoC
3mo ago

vite: `server.fs.deny` bypass on Windows alternate paths

vite: `server.fs.deny` bypass on Windows alternate paths

▾ Midnightvite · viteEPSS 0.58%via GHSA
GHSA-v82c-5c2q-hx9gMedium
3mo ago

Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

▾ Sunlitgrafana · github.com/grafana/grafana-operatorvia GHSA
CVE-2026-49738Low
3mo ago

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

TYPO3 CMS has Broken Access Control in its File Abstraction Layer

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.52%via GHSA
CVE-2026-49742High
3mo ago

TYPO3 CMS has Broken Access Control in its Media Module

TYPO3 CMS has Broken Access Control in its Media Module

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.46%via GHSA
GHSA-g7r4-m6w7-qqqrLow· 2.5
3mo ago

esbuild allows arbitrary file read when running the development server on Windows

esbuild allows arbitrary file read when running the development server on Windows

▾ Sunlitesbuild · esbuildvia GHSA
CVE-2026-54094Medium· 6.8
3mo ago

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.50%via GHSA
CVE-2026-54093Medium
3mo ago

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.19%via GHSA
CVE-2026-40987High· 7.1PoC
3mo ago

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.…

▾ Midnightvmware · spring_integrationEPSS 0.26%via NVD
CVE-2026-48049Medium· 5.3
3mo ago

@hapi/inert has a static-file confinement bypass via sibling-prefix path

@hapi/inert has a static-file confinement bypass via sibling-prefix path

▾ Sunlithapi · @hapi/inertEPSS 0.59%via GHSA
CVE-2026-42305High· 8.8
3mo ago

dulwich: Dulwich: Remote Code Execution via Malicious Git Repository (CVE-2026-42305)

A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.85%via CSAF
CVE-2026-0270High· 7.5
3mo ago

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a ma…

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a ma…

▾ Twilightpaloaltonetworks · cortex_xsoarEPSS 0.20%via NVD
CVE-2026-52726Medium· 5.4⚖ disputed
3mo ago

dulwich: Dulwich: Arbitrary code execution via crafted Git submodules (CVE-2026-52726)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updat…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.68%via CSAF
CVE-2026-32193High· 8.8
3mo ago

Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Azure Kubernetes ServiceEPSS 0.37%via CVEORG
CVE-2026-45454Medium· 6.5
3mo ago

Microsoft SharePoint Remote Code Execution Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 1.5%via CVEORG
CVE-2026-45482High· 8.4
3mo ago

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Microsoft Visual Studio Code CoPilot Chat ExtensionEPSS 0.41%via CVEORG
CVE-2026-47932High· 8.8
3mo ago

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current u…

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current u…

▾ Twilightadobe · coldfusionEPSS 0.51%via NVD
CVE-2026-41843Medium· 5.9
3mo ago

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

▾ Sunlitvmware · spring_frameworkEPSS 0.39%via NVD
CVE-2026-49233High
3mo ago

Routinator has cache path traversal when processing the module component of rsync URIs

Routinator has cache path traversal when processing the module component of rsync URIs

▾ Twilightroutinator · routinatorEPSS 0.50%via GHSA
CVE-2026-47712Low· 3.3
3mo ago

Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`

Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`

▾ Sunlitdulwich · dulwichEPSS 0.18%via GHSA
CVE-2026-7774None
3mo ago

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to…

▾ SunlitEPSS 0.78%via NVD
CVE-2026-35082High· 8.8
3mo ago

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.68%via NVD
CVE-2026-43965Medium· 5.6PoC
3mo ago

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…

▾ TwilightGleam · gleamEPSS 0.19%via NVD
CVE-2026-32685Medium· 4.6PoC
3mo ago

Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporat…

Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporat…

▾ TwilightGleam · gleamEPSS 0.19%via NVD
CVE-2026-8643Medium· 5.5⚖ disputed
3mo ago

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

▾ Sunlitpypa · pipEPSS 0.47%via NVD
CWE-22 vulnerabilities (CVEs) — page 29 · VulnSea