VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1058 CVEsRSS

CVE-2026-93712High· 7.5
5d ago

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and che…

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and che…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-94489Medium· 4.3PoC
5d ago

A vulnerability was identified in OctoPrint 1.0.0

A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename lead…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-61647High· 7.1
6d ago

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-t…

▾ Twilightroomi-fields · notebooklm-mcpEPSS 0.32%via NVD
CVE-2026-59816Medium· 4.3PoC
6d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts o…

▾ Twilightlaurent22 · joplinEPSS 0.36%via NVD
CVE-2026-49453High· 7.0PoC
6d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or pa…

▾ Midnightlaurent22 · joplinEPSS 0.41%via NVD
CVE-2026-79318Medium· 6.5
6d ago

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

▾ SunlitEPSS 0.86%via NVD
CVE-2026-52835High· 7.0PoC
6d ago

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.file…

▾ MidnightTautulli · TautulliEPSS 0.59%via NVD
CVE-2026-62369High· 8.1
6d ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…

▾ Twilightkubeedge · kubeedgeEPSS 0.86%via NVD
CVE-2026-63416Low· 3.7PoC
6d ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL …

▾ Twilightjgraph · drawioEPSS 0.33%via NVD
CVE-2026-53940High· 8.8PoC
6d ago

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

▾ Midnightconda · condaEPSS 0.55%via NVD
CVE-2026-15801High· 8.0⚖ disputed
6d ago

A vulnerability was found in CRI-O related to the container checkpoint and restore feature

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with suffic…

▾ TwilightRed Hat · cri-oEPSS 0.32%via NVD
CVE-2026-94185Medium· 5.5
6d ago

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containi…

▾ Sunlitnvm-sh · nvmEPSS 0.22%via NVD
CVE-2026-94049Medium· 4.3PoC
1w ago

A flaw has been found in 06ketan slideshot up to 4.4.0

A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traversal. The attack is possible to be carr…

▾ Twilight06ketan · slideshotEPSS 0.47%via NVD
CVE-2026-94046Medium· 4.3PoC
1w ago

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPat…

▾ Twilight0215AndrewFeng · ACE-MCPEPSS 0.47%via NVD
CVE-2026-94044High· 7.3
1w ago

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content lead…

▾ Twilight03-lovepreetSingh · MCPEPSS 0.61%via NVD
CVE-2026-94037Medium· 4.3PoC
1w ago

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of…

▾ Twilight00Kisumi00 · mcp-file-analyzerEPSS 0.47%via NVD
CVE-2026-93988Medium· 6.5PoC
1w ago

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email par…

▾ Twilightwebkul · qloappsEPSS 0.55%via NVD
CVE-2026-93992High· 8.1PoC
1w ago

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing dir…

▾ MidnightGopeedLab · gopeedEPSS 0.91%via NVD
CVE-2026-93986Low· 3.1
1w ago

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent…

▾ Sunlitrclone · rcloneEPSS 0.29%via NVD
CVE-2026-85272Medium· 4.3PoC
1w ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved…

▾ Twilightopenedx · openedx-platformEPSS 0.48%via NVD
CVE-2026-84086High· 7.2
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.87%via NVD
CVE-2017-20284High· 7.5PoC
1w ago

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

▾ MidnightCaucho Technology, Inc. · ResinEPSS 0.96%via NVD
CVE-2026-82896High· 7.6
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.49%via NVD
CVE-2026-93751Medium· 6.5
1w ago

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platfor…

▾ Sunlitgarycourt · uri-jsEPSS 0.40%via NVD
CVE-2026-62278High· 8.1
1w ago

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controlle…

▾ Twilighthargata · lubelogEPSS 0.51%via NVD
CVE-2026-63445High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

▾ Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2025-14753High· 7.5
1w ago

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

▾ Twilightibm · cloud_pak_for_dataEPSS 0.46%via NVD
CVE-2026-21822Medium· 6.3
1w ago

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially…

▾ SunlitHCL Software · HCL AppScan 360°EPSS 0.21%via NVD
CVE-2026-40535Medium· 6.5
1w ago

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write …

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write …

▾ SunlitSynology · DiskStation Manager (DSM)EPSS 0.50%via NVD
CVE-2026-40536Medium· 4.3
1w ago

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…

▾ SunlitSynology · DiskStation Manager (DSM)EPSS 0.42%via NVD
CWE-22 vulnerabilities (CVEs) — page 4 · VulnSea