VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-64756Medium· 5.5
1w ago

A path handling issue was addressed with improved validation

A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2026-73496High· 7.7PoC
1w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

▾ Midnightsooperset · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-15955High· 7.5
1w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

▾ TwilightIBM · Db2EPSS 0.40%via NVD
CVE-2026-16335High· 8.1
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.42%via NVD
CVE-2026-89021Medium· 6.9
1w ago

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…

▾ SunlitMikroTik · RouterOSEPSS 0.38%via NVD
CVE-2026-18515Medium· 4.3
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the…

▾ SunlitIBM · iEPSS 0.28%via NVD
CVE-2026-82035High· 7.1
1w ago

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name …

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name …

▾ TwilightPyMuPDF · PyMuPDFEPSS 0.32%via NVD
CVE-2026-90691High· 8.3PoC
1w ago

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API Files Endpoi…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.62%via NVD
CVE-2026-78299Critical· 9.1
1w ago

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

▾ MidnightEclipse Foundation · Eclipse Embedded CDT (C/C++ Development Tools)EPSS 0.54%via NVD
CVE-2026-82428High· 8.8
1w ago

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and pred…

▾ TwilightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.69%via NVD
CVE-2026-82427High· 7.8
1w ago

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in bo…

▾ TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.15%via NVD
CVE-2026-82426Medium· 6.5
1w ago

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. Th…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.42%via NVD
CVE-2026-81565Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was…

▾ Sunlitjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.47%via NVD
CVE-2026-81564High· 7.0
1w ago

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks use…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks use…

▾ Twilightjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.47%via NVD
CVE-2026-54150Medium· 6.9
1w ago

next-video is a library for adding video to Next.js applications

next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/…

▾ Sunlitmuxinc · next-videoEPSS 0.42%via NVD
CVE-2026-54178High· 8.1
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDi…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.56%via NVD
CVE-2026-57119High· 7.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary che…

▾ MidnightMervinPraison · PraisonAIEPSS 0.53%via NVD
CVE-2026-56839High· 7.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy w…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57129High· 7.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, o…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.53%via NVD
CVE-2026-57145Critical· 9.1
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a…

▾ MidnightMervinPraison · PraisonAIEPSS 0.54%via NVD
CVE-2026-54629High· 7.5
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

▾ Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-47253High· 7.3PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll wi…

▾ Midnightjulien040 · anyqueryEPSS 0.44%via NVD
CVE-2026-55832Medium· 6.1PoC
1w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tens…

▾ Twilightsonos · tractEPSS 0.19%via NVD
CVE-2026-55846Medium· 6.2PoC
1w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/ma…

▾ Twilightallure-framework · allure2EPSS 0.18%via NVD
CVE-2026-47256Medium· 5.3PoC
1w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

▾ Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.44%via NVD
CVE-2026-90494Medium· 5.3
2w ago

A flaw has been found in restify node-restify up to 12.0.0

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contac…

▾ Sunlitrestify · node-restifyEPSS 0.77%via NVD
CVE-2026-90774High· 7.5PoC
2w ago

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header …

▾ Midnightorhun · rustypasteEPSS 0.56%via NVD
CVE-2026-85706Critical· 10.0CISA KEV0dayPoC
2w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user c…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user c…

▾ Hadalgitlab · gitlabEPSS 91%via NVD
CVE-2026-87910Medium· 5.7
2w ago

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the loca…

▾ SunlitPython Software Foundation · CPythonEPSS 0.54%via NVD
CWE-22 vulnerabilities (CVEs) — page 8 · VulnSea