VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1058 CVEsRSS

CVE-2026-16777Medium· 4.9
1w ago

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes i…

▾ Sunlitjkohlbach · Store Exporter – Export WooCommerce Products, Orders, Subscriptions, CustomersEPSS 0.66%via NVD
CVE-2026-14323High· 7.5
1w ago

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated att…

▾ Twilightprintcart · Printcart Store – Web to Print Product Designer for WooCommerceEPSS 0.94%via NVD
CVE-2026-70200Critical· 10.0
1w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_logic_appsEPSS 0.93%via NVD
CVE-2026-70009Critical· 9.3
1w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_arcEPSS 0.74%via NVD
CVE-2026-54670Critical· 9.1PoC
1w ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controlle…

▾ AbyssalLabRedesCefetRJ · WeGIAEPSS 0.69%via NVD
CVE-2026-54613Medium· 5.4PoC
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without s…

▾ Twilightgivanz · VvvebEPSS 0.34%via NVD
CVE-2026-54612High· 8.8
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file …

▾ Twilightgivanz · VvvebEPSS 0.76%via NVD
CVE-2026-54520High· 8.1PoC
1w ago

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.…

▾ MidnightvmDeshpande · ai-agent-automationEPSS 0.49%via NVD
CVE-2026-54343High· 8.7
1w ago

Frappe Learning Management System (LMS) is a learning system that helps users structure their content

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The …

▾ Twilightfrappe · lmsEPSS 0.68%via NVD
CVE-2026-53554High· 7.3PoC
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename …

▾ Midnightdataease · SQLBotEPSS 0.41%via NVD
CVE-2026-72697High· 6.5
1w ago

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

▾ Twilightgetgrav · getgrav/gravEPSS 0.46%via GHSA
CVE-2026-72695High· 8.1
1w ago

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

▾ Twilightgetgrav · getgrav/gravEPSS 0.90%via GHSA
CVE-2026-15815High· 8.8
1w ago

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary fi…

▾ TwilightGrafana · Grafana OSSEPSS 0.66%via NVD
CVE-2026-45140Critical· 9.8PoC
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

▾ Abyssalchamilo · chamilo-lmsEPSS 1.3%via NVD
CVE-2026-45723Low· 2.7
1w ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

▾ Sunlitsiderolabs · omniEPSS 0.49%via NVD
CVE-2026-89038Medium· 6.2PoC
1w ago

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

▾ TwilightVerizon · com.vcast.mediamanagerEPSS 0.19%via NVD
CVE-2026-54053Critical· 9.6
1w ago

Many Notes is a Markdown note-taking web application designed for simplicity

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segme…

▾ Midnightbrufdev · many-notesEPSS 0.70%via NVD
CVE-2026-69089High
1w ago

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

▾ Twilightgetgrav · getgrav/gravEPSS 0.55%via GHSA
CVE-2026-54585Medium· 6.0
1w ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malici…

▾ SunlitMidnightBSD · mportEPSS 0.54%via NVD
CVE-2026-54583High· 8.3
1w ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index d…

▾ TwilightMidnightBSD · mportEPSS 0.54%via NVD
CVE-2026-93014High· 7.1PoC
1w ago

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to …

▾ MidnightRosarioSIS · RosarioSISEPSS 0.50%via NVD
CVE-2026-93013Medium· 4.3
1w ago

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…

▾ Sunlitinfiniflow · ragflowEPSS 0.51%via NVD
CVE-2026-86864High· 8.8
1w ago

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options…

▾ Twilightpgadmin · pgadmin_4EPSS 0.58%via NVD
CVE-2026-92970High· 8.8
1w ago

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequence…

▾ Twilighthubzero · hubzero-cmsEPSS 0.82%via NVD
CVE-2026-92945Medium· 4.2
1w ago

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with…

▾ Sunlitpatriksimek · vm2EPSS 0.28%via NVD
CVE-2026-81829Medium· 5.3
1w ago

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch UR…

▾ SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.58%via NVD
CVE-2026-81453Medium· 6.5
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially ex…

▾ SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.44%via NVD
CVE-2026-92919High· 8.1PoC
1w ago

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to …

▾ Midnightcjbi · admin3EPSS 0.58%via NVD
CVE-2026-81481High· 7.5
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially …

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.53%via NVD
CVE-2026-55062High· 8.4PoC
1w ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

▾ Midnightuniget-org · cliEPSS 0.19%via NVD
CWE-22 vulnerabilities (CVEs) — page 5 · VulnSea