VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-90445High· 7.1
2w ago

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attack…

▾ TwilightCISA · MalcolmEPSS 0.52%via NVD
CVE-2026-87727Medium· 6.5
2w ago

a-blog cms Ver

a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.

▾ Sunlitappleple inc. · a-blog cmsEPSS 0.41%via NVD
CVE-2026-87983Critical· 9.2
2w ago

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during…

▾ Midnightmistralai · mistral-vibeEPSS 0.62%via NVD
CVE-2026-19991High· 8.1
2w ago

UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from…

▾ Twilightstiofansisland · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPEPSS 0.41%via CVEORG
CVE-2026-49846High· 7.5
2w ago

libks provides foundational support for signalwire C products

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. Th…

▾ Twilightsignalwire · libksEPSS 0.50%via NVD
CVE-2025-69904Medium· 4.9
2w ago

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive syste…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-59149Medium· 6.5
2w ago

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

▾ Sunlitmockoon · @mockoon/commons-serverEPSS 0.48%via GHSA
CVE-2026-87984Critical· 9.3
2w ago

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permi…

▾ Midnightmistralai · mistral-vibeEPSS 0.50%via NVD
CVE-2026-84889High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

▾ Twilightlangflow · langflowEPSS 0.85%via NVD
CVE-2026-88046Medium· 5.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk…

▾ Sunlitrclone · rcloneEPSS 0.37%via NVD
CVE-2026-77807High· 7.5
2w ago

AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This ma…

▾ Twilightacyba · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressEPSS 0.93%via CVEORG
CVE-2026-84939Critical· 9.1
2w ago

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

▾ Midnightapache · freemarkerEPSS 0.85%via NVD
CVE-2026-81551High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.64%via NVD
CVE-2026-86087Medium· 4.3
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.

▾ Sunlitibm · db2EPSS 0.34%via NVD
CVE-2026-81554High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.77%via NVD
CVE-2025-57231High· 7.5PoC
2w ago

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

▾ MidnightEPSS 1.8%via NVD
CVE-2026-88938Medium· 6.5PoC
2w ago

knowns through 0.33.0 Path Traversal via code.find MCP tool

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal seque…

▾ Twilightknowns-dev · knownsEPSS 0.48%via CVEORG
CVE-2026-81275Medium· 6.5
2w ago

WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability

Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.

▾ SunlitYouzify · youzifyEPSS 0.44%via CVEORG
CVE-2026-88790Medium· 4.8PoC
2w ago

A security vulnerability has been detected in proma-ai Proma up to 0.19.37

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File Preview Service. Such manipulatio…

▾ Twilightproma-ai · PromaEPSS 0.17%via NVD
CVE-2026-82100Critical· 9.6
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.61%via NVD
CVE-2026-80424Critical· 9.1
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.51%via NVD
CVE-2026-45767Medium· 4.4
2w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule lo…

▾ Sunlitoisf · suricataEPSS 0.40%via NVD
CVE-2026-76652Medium· 4.8
2w ago

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote…

▾ SunlitTP-Link Systems Inc. · TL-MR6400 v8EPSS 0.73%via NVD
CVE-2026-18386Medium· 4.9
2w ago

WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter

The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with a…

▾ Sunlitcssimmon · WP BackItUp Community EditionEPSS 0.73%via CVEORG
CVE-2026-78085Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.50%via CVEORG
CVE-2026-88940Medium· 5.3PoC
2w ago

knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to loc…

▾ Twilightknowns-dev · knownsEPSS 0.56%via CVEORG
CVE-2026-88937High· 8.8PoC
2w ago

knowns through 0.33.0 Path Traversal via Template Engine

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates t…

▾ Midnightknowns-dev · knownsEPSS 0.65%via CVEORG
CVE-2026-81540High· 8.5
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.55%via NVD
CVE-2026-81789High· 8.6
2w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

▾ TwilightStudio Wombat · Advanced Product Fields Extended for WooCommerceEPSS 0.53%via NVD
CVE-2026-88014Medium· 6.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.N…

▾ Sunlitrclone · rcloneEPSS 0.20%via NVD
CWE-22 vulnerabilities (CVEs) — page 9 · VulnSea