VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-27606Critical· 9.8PoC
7mo ago

Rollup is a module bundler for JavaScript

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure …

▾ Abyssalrollupjs · rollupEPSS 1.5%via NVD
CVE-2026-22860High· 7.5
7mo ago

Rack is a modular Ruby web server interface

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root i…

▾ Twilightrack · rackEPSS 0.68%via NVD
CVE-2026-20615High· 7.8
7mo ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to gain root privileges.

▾ Twilightapple · ipadosEPSS 0.16%via NVD
CVE-2025-43417Medium· 5.5
7mo ago

A path handling issue was addressed with improved logic

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access user-sensitive data.

▾ Sunlitapple · macosEPSS 0.21%via NVD
CVE-2026-0651High· 7.8PoC
7mo ago

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and fa…

▾ Midnighttp-link · tapo_c260_firmwareEPSS 0.32%via NVD
CVE-2026-25640High· 7.1
7mo ago

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript …

▾ Twilightpydantic · pydantic_aiEPSS 0.41%via NVD
CVE-2026-24842High· 8.2
8mo ago

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attac…

▾ Twilightisaacs · tarEPSS 0.62%via NVD
CVE-2020-36939High· 7.5PoC
8mo ago

Cassandra Web - Remote File Read

Cassandra Web - Remote File Read

▾ Midnightcassandra-web · cassandra-webEPSS 2.9%via GHSA
CVE-2026-24486High· 8.6PoC
8mo ago

Python-Multipart is a streaming multipart parser for Python

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …

▾ Midnightfastapiexpert · python-multipartEPSS 2.2%via NVD
CVE-2023-7335None
8mo ago

EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality

EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] para…

▾ SunlitEPSS 0.77%via NVD
CVE-2026-24049High· 7.1PoC
8mo ago

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after e…

▾ Midnightwheel_project · wheelEPSS 0.36%via NVD
CVE-2026-24046High· 7.1
8mo ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-23745Medium· 6.1PoC
8mo ago

node-tar is a Tar for Node.js

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass…

▾ Twilightisaacs · tarEPSS 0.38%via NVD
CVE-2025-61686Critical· 9.1PoC
8mo ago

React Router is a router for React

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…

▾ Abyssalshopify · react-router/nodeEPSS 18%via NVD
CVE-2025-68428High· 7.5PoC
8mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsani…

▾ Midnightparall · jspdfEPSS 2.2%via NVD
CVE-2022-50796Critical· 9.8
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to th…

▾ Midnightsound4 · stream_extensionEPSS 1.6%via NVD
CVE-2025-68476None
9mo ago

KEDA is a Kubernetes-based Event Driven Autoscaling component

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication…

▾ SunlitEPSS 0.55%via NVD
CVE-2025-34452None
9mo ago

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the ser…

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the ser…

▾ SunlitEPSS 5.4%via NVD
CVE-2025-13339High· 7.5PoC
9mo ago

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the…

▾ MidnightEPSS 2.2%via NVD
CVE-2025-61811Critical· 9.1
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could leverage…

▾ Midnightadobe · coldfusionEPSS 1.2%via NVD
CVE-2025-60024High· 8.8
9mo ago

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticat…

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticat…

▾ Twilightfortinet · fortivoiceEPSS 0.46%via NVD
CVE-2025-65879High· 8.1
9mo ago

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH a…

▾ Twilightyeqifu · warehouse_management_systemEPSS 0.79%via NVD
CVE-2025-65878High· 7.5
9mo ago

The warehouse management system version 1.2 contains an arbitrary file read vulnerability

The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbi…

▾ Twilightyeqifu · warehouse_management_systemEPSS 0.70%via NVD
CVE-2025-65897High· 8.8
9mo ago

zdh_web is a data collection, processing, monitoring, scheduling, and management platform

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to t…

▾ Twilightzhaoyachao · zdh_webEPSS 0.75%via NVD
CVE-2025-64057High· 8.3
9mo ago

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

▾ Twilightfanvil · x210_firmwareEPSS 0.81%via NVD
CVE-2025-54160High· 7.8
9mo ago

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

▾ Twilightsynology · beedriveEPSS 0.20%via NVD
CVE-2025-29846High· 7.2
9mo ago

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

▾ Twilightsynology · router_managerEPSS 0.64%via NVD
CVE-2025-29845Medium· 4.3
9mo ago

A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

▾ Sunlitsynology · router_managerEPSS 0.43%via NVD
CVE-2025-29844Medium· 4.3
9mo ago

A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

▾ Sunlitsynology · router_managerEPSS 0.43%via NVD
CVE-2025-29843Medium· 5.4
9mo ago

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

▾ Sunlitsynology · router_managerEPSS 0.37%via NVD
CWE-22 vulnerabilities (CVEs) — page 32 · VulnSea