VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-28265Medium· 4.4
5mo ago

PowerStore, contains a Path Traversal vulnerability in the Service user

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

▾ Sunlitdell · powerstoreosEPSS 0.16%via NVD
CVE-2026-3987High· 7.2
5mo ago

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.

▾ Twilightwatchguard · firewareEPSS 1.1%via NVD
CVE-2026-20174Medium· 4.9
5mo ago

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the…

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the…

▾ Sunlitcisco · nexus_dashboard_insightsEPSS 0.49%via NVD
CVE-2026-34451Medium· 5.4
6mo ago

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated …

▾ Sunlitanthropic · claude_sdk_for_typescriptEPSS 0.39%via NVD
CVE-2026-29870High· 7.6
6mo ago

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normaliz…

▾ TwilightEPSS 0.80%via NVD
CVE-2026-33581Medium· 6.5
6mo ago

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers …

▾ Sunlitopenclaw · openclawEPSS 0.64%via NVD
CVE-2026-30286Critical· 9.8
6mo ago

An arbitrary file overwrite vulnerability in Funambol, Inc

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Midnightfunambol · zefiroEPSS 0.83%via NVD
CVE-2026-30283Critical· 9.8
6mo ago

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information expo…

▾ Midnightpeaksel · animal_sounds_and_ringtonesEPSS 0.80%via NVD
CVE-2026-30282Critical· 9.0
6mo ago

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

▾ Midnightuxgroupllc · cast_to_tvEPSS 0.57%via NVD
CVE-2026-30279High· 8.4
6mo ago

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Twilightsquareapps · my_locationEPSS 0.21%via NVD
CVE-2026-30278Critical· 9.8
6mo ago

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Midnightfunair · fly_is_funEPSS 0.77%via NVD
CVE-2026-30277High· 8.4
6mo ago

An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Twilighttriumph-adler · mobile_printEPSS 0.21%via NVD
CVE-2026-5203Medium· 4.7PoC
6mo ago

A vulnerability was found in CMS Made Simple up to 2.2.22

A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulati…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34070High· 7.5PoC
6mo ago

LangChain is a framework for building agents and LLM-powered applications

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…

▾ Midnightlangchain · langchain_coreEPSS 1.2%via NVD
CVE-2026-33748Medium· 6.5
6mo ago

github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748)

A flaw was found in BuildKit. Insufficient validation of Git URL fragment subdirectory components may allow a remote attacker to access files outside the checked-out Git repository root. This access is limited to files on the same mounted …

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.53%via CSAF
CVE-2026-33747High· 8.2
6mo ago

BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747)

A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state …

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.58%via CSAF
CVE-2026-5027High· 8.8PoC
6mo ago

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

▾ Midnightlangflow · langflowEPSS 4.8%via NVD
CVE-2026-0964Medium· 6.3
6mo ago

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user exec…

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user exec…

▾ Sunlitlibssh · libsshEPSS 0.41%via NVD
CVE-2025-67030High· 8.8
6mo ago

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

▾ Twilightcodehaus-plexus · plexus-utilsEPSS 0.66%via NVD
CVE-2026-22739High· 8.6PoC
6mo ago

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…

▾ Midnightvmware · spring_cloud_configEPSS 1.2%via NVD
CVE-2026-33211Critical· 9.6
6mo ago

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path tr…

▾ Midnightlinuxfoundation · tekton_pipelinesEPSS 0.70%via NVD
CVE-2026-33236High· 8.1
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the…

▾ Twilightnltk · nltkEPSS 0.71%via NVD
CVE-2026-33001High· 8.8
6mo ago

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted on…

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted on…

▾ Twilightjenkins · jenkinsEPSS 1.2%via NVD
CVE-2026-32981High· 7.5
6mo ago

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can …

▾ Twilightanyscale · rayEPSS 1.0%via NVD
CVE-2026-23942Medium· 5.4
6mo ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and progr…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and progr…

▾ Sunliterlang · erlang/otpEPSS 0.36%via NVD
CVE-2026-23907Medium· 5.3PoC
6mo ago

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that i…

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that i…

▾ Twilightapache · pdfbox-examplesEPSS 0.89%via NVD
CVE-2026-29786Medium· 6.3PoC
6mo ago

node-tar is a full-featured Tar for Node.js

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables f…

▾ Twilightisaacs · tarEPSS 0.39%via NVD
CVE-2026-24457Critical· 9.1
6mo ago

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In s…

▾ Midnighteclipse · openmqEPSS 0.62%via NVD
CVE-2026-0847High· 8.6PoC
6mo ago

Path Traversal in nltk/nltk

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fa…

▾ Midnightnltk · nltk/nltkEPSS 0.90%via CVEORG
CVE-2026-23939Medium· 6.9
7mo ago

Path Traversal in Local File Store Backend

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib…

▾ Sunlithexpm · hexpm/hexpmEPSS 0.43%via CVEORG
CWE-22 vulnerabilities (CVEs) — page 31 · VulnSea