VulnSea

CWE-23

CVEs classified under CWE-23, newest first.

64 CVEsRSS

CVE-2026-23734None
4mo ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwi…

▾ SunlitEPSS 20%via NVD
CVE-2026-31927Medium· 4.9
5mo ago

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

▾ Sunlitanviz · cx7_firmwareEPSS 0.52%via NVD
CVE-2026-21620None
7mo ago

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. Thi…

▾ SunlitEPSS 0.48%via NVD
CVE-2025-67366High· 7.5
8mo ago

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises fr…

▾ Twilightsylphx · filesystem_mcpEPSS 0.61%via NVD
CWE-23 vulnerabilities (CVEs) — page 3 · VulnSea