VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1059 CVEsRSS

CVE-2026-79705Medium· 4.5
1w ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

▾ SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.38%via NVD
CVE-2026-47215Medium· 4.8
1w ago

SingularityCE and SingularityPRO are open source container platforms

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a conta…

▾ Sunlitsylabs · singularityEPSS 0.15%via NVD
CVE-2026-87791High· 8.7
1w ago

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible …

▾ TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.54%via NVD
CVE-2026-91934High· 8.8
1w ago

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to sy…

▾ TwilightFlowiseAI · FlowiseEPSS 0.74%via NVD
CVE-2026-91940High· 7.5PoC
1w ago

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies w…

▾ Midnightunclecode · crawl4aiEPSS 0.46%via NVD
CVE-2026-91989High· 7.5
1w ago

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass …

▾ Twilightdep0we · atomic-agents-stackEPSS 1.3%via NVD
CVE-2026-17495Medium· 5.9
1w ago

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal…

▾ Sunlitmoment · momentEPSS 0.36%via NVD
CVE-2026-91771High· 8.8
1w ago

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal s…

▾ Twilightwandb · wandbEPSS 1.2%via NVD
CVE-2026-91751High· 8.3PoC
1w ago

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal seq…

▾ Midnightflextype · flextypeEPSS 0.54%via NVD
CVE-2026-50024Medium· 5.3
1w ago

GitHacker is a tool that restores Git repositories from exposed .git directories

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs…

▾ SunlitWangYihang · GitHackerEPSS 0.45%via NVD
CVE-2026-54561Medium· 6.2PoC
1w ago

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path …

▾ Twilightmkreyman · mcp-memory-keeperEPSS 0.25%via NVD
CVE-2026-54077High· 7.1
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integrat…

▾ TwilightArcadeData · arcadedbEPSS 0.45%via NVD
CVE-2026-48785Medium· 4.8
1w ago

Apptainer is an open source container platform

Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also author…

▾ Sunlitapptainer · apptainerEPSS 0.15%via NVD
CVE-2026-55828Medium· 6.0
1w ago

qbee transport is a remote access transport protocol implementation

qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A c…

▾ Sunlitqbee-io · transportEPSS 0.38%via NVD
CVE-2026-91200High· 8.8
1w ago

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the d…

▾ Twilightdevspace · devspaceEPSS 0.65%via NVD
CVE-2026-84624Medium· 5.5
1w ago

A permissions issue was addressed with improved path validation

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able …

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2026-86910Medium· 5.5
1w ago

A permissions issue was addressed with improved path validation

A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2026-65411Medium· 5.5
1w ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.

▾ Sunlitapple · ipadosEPSS 0.17%via NVD
CVE-2026-84541Medium· 5.5
1w ago

An input validation issue was addressed with improved input validation

An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An application may be able to access restricted files.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2026-84598High· 7.5
1w ago

A path traversal issue was addressed with improved path validation

A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a trust-paired device may be able to read and write arbitrary …

▾ Twilightapple · ipadosEPSS 0.50%via NVD
CVE-2026-64790High· 7.8
1w ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges.

▾ Twilightapple · macosEPSS 0.19%via NVD
CVE-2026-86886Medium· 5.5
1w ago

A path traversal issue was addressed with improved input validation

A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.

▾ Sunlitapple · ipadosEPSS 0.17%via NVD
CVE-2026-43791Medium· 6.5
1w ago

A validation issue was addressed with improved input sanitization

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to read arbitrary files.

▾ Sunlitapple · macosEPSS 0.46%via NVD
CVE-2026-65382Medium· 5.5
1w ago

A parsing issue in the handling of directory paths was addressed with improved path validation

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2026-84568High· 7.8PoC
1w ago

A path traversal issue was addressed with improved path validation

A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrar…

▾ Midnightapple · macosEPSS 0.19%via NVD
CVE-2026-86902Medium· 5.5
1w ago

A parsing issue in the handling of directory paths was addressed with improved path validation

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2026-43691High· 7.8
1w ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

▾ Twilightapple · macosEPSS 0.19%via NVD
CVE-2026-84534Medium· 5.5
1w ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafte…

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2026-64756Medium· 5.5
1w ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2026-73496High· 7.7PoC
1w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

▾ Midnightsooperset · mcp-atlassianEPSS 0.48%via NVD
CWE-22 vulnerabilities (CVEs) — page 7 · VulnSea