VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

895 CVEsRSS

CVE-2026-92816High· 7.8PoC
5d ago

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled con…

MidnightComfy-Org · ComfyUIEPSS 0.16%via NVD
CVE-2026-87976High· 8.1
5d ago

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coord…

Twilightapache · nifiEPSS 0.39%via NVD
CVE-2026-89084High· 8.8
5d ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

TwilightHP Inc · HP AC Print & ScanEPSS 0.58%via NVD
CVE-2026-86071Low· 3.7
5d ago

Junrar is an open source Java RAR archive library

Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a cr…

Sunlitjunrar · junrarEPSS 0.30%via NVD
CVE-2026-63225Medium· 4.4
5d ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…

SunlitRedocly · redocly-cliEPSS 0.17%via NVD
CVE-2026-92604High· 8.1PoC
5d ago

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path trave…

MidnightStamusNetworks · sciriusEPSS 0.53%via NVD
CVE-2026-59974High· 7.8PoC
5d ago

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource …

Midnightstanfordnlp · stanzaEPSS 0.47%via NVD
CVE-2026-59944Medium· 6.1
5d ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates litera…

Sunlitcomposer · composerEPSS 0.45%via NVD
CVE-2026-85731High· 8.8PoC
5d ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

Midnightoras-project · oras-goEPSS 0.67%via NVD
CVE-2026-76409High· 8.8
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

TwilightCisco · Cisco Nexus DashboardEPSS 0.50%via NVD
CVE-2026-76434Medium· 4.9
5d ago

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this …

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.27%via NVD
CVE-2026-76433Medium· 5.3
5d ago

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient vali…

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient vali…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.93%via NVD
CVE-2026-76432Medium· 4.9
5d ago

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability…

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.88%via NVD
CVE-2026-76431Medium· 4.9
5d ago

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploi…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 1.1%via NVD
CVE-2026-92137High· 8.8
5d ago

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Config…

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Config…

TwilightJenkins Project · Jenkins Robot Framework PluginEPSS 0.78%via NVD
CVE-2026-92131Medium· 4.2
5d ago

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside…

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside…

SunlitJenkins Project · Jenkins Pipeline: Groovy Libraries PluginEPSS 0.22%via NVD
CVE-2026-92355High· 8.7
5d ago

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

TwilightOctopus Deploy · Octopus ServerEPSS 0.68%via NVD
CVE-2026-76555Medium· 6.8
5d ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP …

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP …

SunlitEPSS 0.45%via NVD
CVE-2026-83357High· 8.1
6d ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle …

TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVMEPSS 0.38%via NVD
CVE-2026-61560Critical· 9.8PoC
6d ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from th…

Abyssalzereight · @zereight/mcp-gitlabEPSS 0.70%via NVD
CVE-2026-89040Critical· 9.8
6d ago

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code…

MidnightTencent · Mass Service Engine in Cluster (MSEC)EPSS 0.93%via NVD
CVE-2026-51134High· 7.5PoC
6d ago

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

MidnightEPSS 1.9%via NVD
CVE-2026-81568High· 8.7
6d ago

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concate…

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concate…

Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.33%via NVD
CVE-2026-69201Medium· 5.9
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request contai…

Sunlithttp4s · org.http4s:http4s-server_2.12EPSS 0.63%via NVD
CVE-2026-57442Medium· 6.9PoC
6d ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules pa…

Twilightbitbonsai · mcpvaultEPSS 0.17%via NVD
CVE-2026-79705Medium· 4.5
6d ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.25%via NVD
CVE-2026-47215Medium· 4.8
6d ago

SingularityCE and SingularityPRO are open source container platforms

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a conta…

Sunlitsylabs · singularityEPSS 0.15%via NVD
CVE-2026-87791High· 8.7
6d ago

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible …

TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.40%via NVD
CVE-2026-91934High· 8.8
6d ago

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to sy…

TwilightFlowiseAI · FlowiseEPSS 0.69%via NVD
CVE-2026-91940High· 7.5PoC
6d ago

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies w…

Midnightunclecode · crawl4aiEPSS 0.42%via NVD
CWE-22 vulnerabilities (CVEs) — page 3 · VulnSea