VulnSea

CWE-23

CVEs classified under CWE-23, newest first.

61 CVEsRSS

CVE-2026-93468High· 7.5
3d ago

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

TwilightHGiga · OAKlouds-bulletin_v3-2.0EPSS 0.46%via NVD
CVE-2026-55062High· 8.4
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

Twilightuniget-org · cliEPSS 0.13%via NVD
CVE-2026-76424High· 7.2
5d ago

A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations

A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker c…

TwilightCisco · Cisco Identity Services Engine SoftwareEPSS 0.62%via NVD
CVE-2026-50024Medium· 5.3
6d ago

GitHacker is a tool that restores Git repositories from exposed .git directories

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs…

SunlitWangYihang · GitHackerEPSS 0.44%via NVD
CVE-2026-76440Critical· 9.8
1w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review r…

MidnightCisco · Cisco Secure EmailEPSS 0.45%via NVD
CVE-2023-32778Low· 3.3
1w ago

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

SunlitILIAS · ILIASEPSS 0.22%via NVD
CVE-2023-45858High· 8.6
1w ago

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

TwilightPaessler · PRTG Network MonitorEPSS 0.66%via NVD
CVE-2023-40772Medium· 4.3PoC
1w ago

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

TwilightDataEase · DataEaseEPSS 1.0%via NVD
CVE-2023-29377Medium· 6.60day
1w ago

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA …

MidnightSofting · Secure Integration ServerEPSS 0.48%via NVD
CVE-2026-82768High· 8.1
1w ago

Path traversal vulnerability exists in SGA1000

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

TwilightContec Co., Ltd. · SGA1000EPSS 0.35%via NVD
CVE-2026-82765High· 8.1
1w ago

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

TwilightContec Co., Ltd. · FXA5000EPSS 0.32%via NVD
CVE-2026-59149Medium· 6.5
1w ago

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

Sunlitmockoon · @mockoon/commons-serverEPSS 0.48%via GHSA
CVE-2026-89065High· 7.1
1w ago

Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the…

Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the…

TwilightAWS · projenEPSS 0.15%via NVD
CVE-2026-84939Critical· 9.1
1w ago

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

Midnightapache · freemarkerEPSS 0.83%via NVD
CVE-2026-79728Medium· 6.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit thi…

Sunlitdell · secure_connect_gatewayEPSS 0.22%via NVD
CVE-2026-15913High· 7.7
1w ago

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achi…

TwilightFortra · GoAnywhere MFTEPSS 0.39%via NVD
CVE-2026-87747Medium· 4.9
1w ago

The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability

The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.

SunlitRagic · Enterprise Cloud DatabaseEPSS 0.41%via NVD
CVE-2026-47680Medium· 5.3
1w ago

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to infl…

Sunlitfluxcd · source-controllerEPSS 0.33%via NVD
CVE-2026-77897High· 7.0
1w ago

Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Power Automate agent for virtual desktopsEPSS 0.27%via NVD
CVE-2026-72948Medium· 6.7
1w ago

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.37%via NVD
CVE-2026-67367High· 8.6
1w ago

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1…

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1…

TwilightSiemens · SIMOVE Fleetmanager V3.1EPSS 0.81%via NVD
CVE-2026-80130High· 7.1
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this …

Twilightdell · secure_connect_gatewayEPSS 0.40%via NVD
CVE-2026-80133High· 7.4
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit thi…

Twilightdell · secure_connect_gatewayEPSS 0.60%via NVD
CVE-2026-78254High· 7.4
2w ago

The ftp and scp tasks of Apache Ant can download files from a remote server

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite…

Twilightapache · antEPSS 0.54%via NVD
CVE-2026-59832High· 7.7
2w ago

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.46%via OSV
CVE-2026-66897Critical· 9.9
4w ago

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing targ…

Midnightcanonical · lxdEPSS 0.67%via NVD
GHSA-w8j7-39hp-8x59Medium
4w ago

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
CVE-2026-53528High· 8.8
1mo ago

LeafWiki is a self-hosted wiki

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWik…

Twilightperber · leafwikiEPSS 0.35%via NVD
CVE-2026-63509Critical· 9.9
1mo ago

Microsoft Fabric Elevation of Privilege Vulnerability

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft FabricEPSS 0.62%via CVEORG
CVE-2026-63490High· 7.5
1mo ago

Handlebars.java provides logic-less and semantic Mustache templates with Java

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…

Twilightgithub · com.github.jknack:handlebars-springmvcEPSS 0.47%via NVD
CWE-23 vulnerabilities (CVEs) · VulnSea