VulnSea

CWE-24

CVEs classified under CWE-24, newest first.

6 CVEsRSS

CVE-2026-34151High· 8.2
1w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix w…

Twilightxwiki · xwiki-platformEPSS 0.54%via NVD
CVE-2025-70819Medium· 6.3
1w ago

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

SunlitZettlab · D6 UltraEPSS 0.11%via NVD
CVE-2026-73573Low· 3.1
1mo ago

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this v…

SunlitEPSS 0.30%via NVD
CVE-2026-48047None
1mo ago

XWiki Platform WebJars API is a package for XWiki, a generic wiki platform

XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get…

SunlitEPSS 0.43%via NVD
CVE-2026-41082High· 7.3
5mo ago

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Twilightocaml · opamEPSS 0.21%via NVD
CVE-2024-1459Medium· 5.3
2y ago

A path traversal vulnerability was found in Undertow

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or res…

Sunlitredhat · undertowEPSS 1.7%via NVD
CWE-24 vulnerabilities (CVEs) · VulnSea