VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1059 CVEsRSS

CVE-2026-55062High· 8.4PoC
1w ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

▾ Midnightuniget-org · cliEPSS 0.19%via NVD
CVE-2026-54617Critical· 9.8
1w ago

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274…

▾ MidnightGravitLauncher · LauncherEPSS 0.68%via NVD
CVE-2026-92748High· 8.8PoC
1w ago

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in th…

▾ MidnightBC-SECURITY · EmpireEPSS 0.82%via NVD
CVE-2026-92791High· 7.5PoC
1w ago

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments i…

▾ Midnightuber · krakenEPSS 0.61%via NVD
CVE-2026-92812Medium· 6.8PoC
1w ago

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the rep…

▾ Twilightdecaporg · decap-serverEPSS 0.42%via NVD
CVE-2026-92816High· 7.8PoC
1w ago

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled con…

▾ MidnightComfy-Org · ComfyUIEPSS 0.20%via NVD
CVE-2026-87976High· 8.1
1w ago

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coord…

▾ Twilightapache · nifiEPSS 0.79%via NVD
CVE-2026-89084High· 8.8
1w ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

▾ TwilightHP Inc · HP AC Print & ScanEPSS 0.78%via NVD
CVE-2026-86071Low· 3.7
1w ago

Junrar is an open source Java RAR archive library

Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a cr…

▾ Sunlitjunrar · junrarEPSS 0.36%via NVD
CVE-2026-63225Medium· 4.4
1w ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…

▾ SunlitRedocly · redocly-cliEPSS 0.18%via NVD
CVE-2026-92604High· 8.1PoC
1w ago

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path trave…

▾ MidnightStamusNetworks · sciriusEPSS 0.58%via NVD
CVE-2026-59974High· 7.8PoC
1w ago

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource …

▾ Midnightstanfordnlp · stanzaEPSS 0.40%via NVD
CVE-2026-59944Medium· 6.1
1w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates litera…

▾ Sunlitcomposer · composerEPSS 0.32%via NVD
CVE-2026-85731High· 8.8PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

▾ Midnightoras-project · oras-goEPSS 0.63%via NVD
CVE-2026-76409High· 8.8
1w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ TwilightCisco · Cisco Nexus DashboardEPSS 0.53%via NVD
CVE-2026-76434Medium· 4.9
1w ago

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this …

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.38%via NVD
CVE-2026-76433Medium· 5.3
1w ago

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient vali…

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient vali…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 1.3%via NVD
CVE-2026-76432Medium· 4.9
1w ago

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability…

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 1.2%via NVD
CVE-2026-76431Medium· 4.9
1w ago

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploi…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 1.2%via NVD
CVE-2026-92137High· 8.8
1w ago

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Config…

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Config…

▾ TwilightJenkins Project · Jenkins Robot Framework PluginEPSS 0.83%via NVD
CVE-2026-92131Medium· 4.2
1w ago

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside…

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside…

▾ SunlitJenkins Project · Jenkins Pipeline: Groovy Libraries PluginEPSS 0.23%via NVD
CVE-2026-92355High· 8.7
1w ago

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

▾ TwilightOctopus Deploy · Octopus ServerEPSS 0.69%via NVD
CVE-2026-76555Medium· 6.8
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP …

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP …

▾ SunlitEPSS 0.47%via NVD
CVE-2026-83357High· 8.1
1w ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle …

▾ TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVMEPSS 0.45%via NVD
CVE-2026-61560Critical· 9.8PoC
1w ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from th…

▾ Abyssalzereight · @zereight/mcp-gitlabEPSS 0.81%via NVD
CVE-2026-89040Critical· 9.8
1w ago

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code…

▾ MidnightTencent · Mass Service Engine in Cluster (MSEC)EPSS 1.1%via NVD
CVE-2026-51134High· 7.5PoC
1w ago

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

▾ MidnightEPSS 1.7%via NVD
CVE-2026-81568High· 8.7
1w ago

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concate…

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concate…

▾ Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.50%via NVD
CVE-2026-69201Medium· 5.9
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request contai…

▾ Sunlithttp4s · org.http4s:http4s-server_2.12EPSS 0.76%via NVD
CVE-2026-57442Medium· 6.9PoC
1w ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules pa…

▾ Twilightbitbonsai · mcpvaultEPSS 0.19%via NVD
CWE-22 vulnerabilities (CVEs) — page 6 · VulnSea