VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2018-25421Medium· 6.5
4mo ago

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile an…

▾ SunlitEPSS 0.33%via NVD
CVE-2018-25408High· 7.5
4mo ago

The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter

The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply director…

▾ TwilightEPSS 0.64%via NVD
CVE-2026-44650Critical· 9.1
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint …

▾ MidnightEPSS 0.83%via NVD
CVE-2026-45668None
4mo ago

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traver…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-45661Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during app…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-44973High· 8.1
4mo ago

github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)

A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…

▾ TwilightRed Hat · Multicluster Engine for KubernetesEPSS 0.47%via CSAF
CVE-2026-20685Medium· 6.5PoC
4mo ago

An attacker in a privileged network position may be able to leak sensitive information

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

▾ Twilightapple · private_cloud_computeEPSS 0.27%via NVD
CVE-2026-34653High· 8.7
4mo ago

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arb…

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arb…

▾ Twilightadobe · commerceEPSS 1.0%via NVD
CVE-2026-34664Medium· 6.3
4mo ago

Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read

Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit t…

▾ Sunlitadobe · substance_3d_designerEPSS 0.29%via NVD
CVE-2026-2614High· 7.5PoC
4mo ago

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue…

▾ Midnightlfprojects · mlflowEPSS 3.2%via NVD
CVE-2026-8069High· 7.8PoC
4mo ago

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigu…

▾ Midnightacer · nitrosenseEPSS 0.17%via NVD
CVE-2026-39817Medium· 5.9
4mo ago

Invoking "go tool pack" does not sanitize output paths in cmd/go

Invoking "go tool pack" does not sanitize output paths in cmd/go

▾ Sunlittoolchain · toolchainEPSS 0.16%via OSV
CVE-2026-35397High· 8.8PoC
4mo ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…

▾ Midnightjupyter · jupyter_serverEPSS 0.67%via NVD
CVE-2026-6321High· 7.5
4mo ago

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct …

▾ Twilightopenjsf · fast-uriEPSS 0.77%via NVD
CVE-2026-7680Medium· 4.3
4mo ago

A weakness has been identified in jsbroks COCO Annotator up to 0.11.1

A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipulation of the argument folder can lead…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-3087High· 7.5
5mo ago

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Window…

▾ Twilightpython · pythonEPSS 0.73%via NVD
CVE-2026-41140High· 8.7
5mo ago

poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)

A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked int…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.6EPSS 0.47%via CSAF
CVE-2026-41245Medium· 5.9
5mo ago

Junrar is an open source java RAR archive library

Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories wh…

▾ Sunlitjunrar_project · junrarEPSS 0.53%via NVD
CVE-2026-41082High· 7.3
5mo ago

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

▾ Twilightocaml · opamEPSS 0.22%via NVD
CVE-2026-6855High· 7.1
5mo ago

instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.22%via CSAF
CVE-2026-20180Critical· 9.9PoC
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Abyssalcisco · identity_services_engineEPSS 6.0%via NVD
CVE-2026-20148Medium· 4.9
5mo ago

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must …

▾ Sunlitcisco · identity_services_engineEPSS 6.5%via NVD
CVE-2026-27305High· 8.6
5mo ago

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this…

▾ Twilightadobe · coldfusionEPSS 1.0%via NVD
CVE-2026-32146High· 7.8PoC
5mo ago

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into f…

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into f…

▾ Midnightlpil · gleamEPSS 0.22%via NVD
CVE-2026-40024High· 7.1
5mo ago

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path…

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path…

▾ Twilightsleuthkit · the_sleuth_kitEPSS 0.21%via NVD
CVE-2026-26058Medium· 6.1
5mo ago

Zulip is an open-source team collaboration tool

Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes t…

▾ Sunlitzulip · zulipEPSS 0.19%via NVD
CVE-2026-22661High· 8.1
5mo ago

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized filenames contain…

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized filenames contain…

▾ Twilightfka · prompts.chatEPSS 0.36%via NVD
CVE-2026-28373Critical· 9.6
5mo ago

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path …

▾ Midnightstackfield · stackfieldEPSS 0.59%via NVD
CVE-2026-4350High· 8.1PoC
5mo ago

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter…

▾ MidnightEPSS 0.53%via NVD
CVE-2026-34978Medium· 6.5
5mo ago

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a r…

▾ Sunlitopenprinting · cupsEPSS 0.42%via NVD
CWE-22 vulnerabilities (CVEs) — page 30 · VulnSea