VulnSea

CWE-36

CVEs classified under CWE-36, newest first.

15 CVEsRSS

CVE-2026-55062High· 8.4
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

Twilightuniget-org · cliEPSS 0.13%via NVD
CVE-2025-70820Low· 3.5
1w ago

Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

SunlitZettlab · D6 UltraEPSS 0.18%via NVD
CVE-2026-89009Critical· 9.1PoC
1w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…

AbyssalWAVLINK Technology · WN535M1EPSS 0.68%via NVD
CVE-2026-82092High· 8.8
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.54%via NVD
CVE-2026-68487Critical· 9.9
1w ago

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

MidnightWebPros · PleskEPSS 0.41%via CVEORG
CVE-2026-88288Medium· 6.5
1w ago

GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.

GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.

SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.37%via NVD
CVE-2026-69612High· 7.8
1w ago

Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.35%via NVD
CVE-2026-68896High· 7.8
1w ago

Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 11 version 23H2EPSS 0.35%via NVD
CVE-2026-46345High· 8.4
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does …

Twilightcompliance-trestle · compliance-trestleEPSS 0.23%via NVD
CVE-2026-47243Critical· 9.2PoC
1mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root t…

Abyssalkata-containers · kata-containersEPSS 0.35%via NVD
CVE-2026-57211Medium· 6.5
2mo ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path v…

SunlitEPSS 0.63%via NVD
CVE-2026-58300Medium· 6.2
2mo ago

Microsoft Edge for Android Information Disclosure Vulnerability

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.45%via CVEORG
CVE-2026-0846High· 8.6PoC
6mo ago

Arbitrary File Read via Absolute Path Input in nltk.util.filestring()

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…

Midnightnltk · nltk/nltkEPSS 0.43%via CVEORG
CVE-2026-20834Medium· 4.6
8mo ago

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

Sunlitmicrosoft · windows_10_1607EPSS 0.75%via NVD
CVE-2018-20250High· 7.8CISA KEVPoC
7y ago

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (ex…

Abyssalrarlab · winrarEPSS 96%via NVD
CWE-36 vulnerabilities (CVEs) · VulnSea