VulnSea

CWE-377

CVEs classified under CWE-377, newest first.

9 CVEsRSS

CVE-2026-54584Medium· 5.3
today

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport …

SunlitMidnightBSD · mportvia NVD
CVE-2026-40635Medium· 5.4
1w ago

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tamper…

Sunlitdell · powerscale_onefsEPSS 0.23%via NVD
CVE-2026-47852High· 7.5
3w ago

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

Twilightvmware · spring_aiEPSS 0.20%via NVD
CVE-2026-63404None
3w ago

Faktory is a language-agnostic background job server

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and es…

SunlitEPSS 0.15%via NVD
CVE-2026-55086Medium· 4.2
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared wo…

Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.18%via NVD
CVE-2026-53759Low
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed att…

Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.25%via NVD
CVE-2026-35342Low· 3.3
2mo ago

mktemp: empty TMPDIR creates temp files in CWD instead of /tmp

mktemp: empty TMPDIR creates temp files in CWD instead of /tmp

Sunlituu_mktemp · uu_mktempEPSS 0.13%via GHSA
CVE-2026-46406Medium
2mo ago

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

Sunlitanthropic-ai · @anthropic-ai/claude-codeEPSS 0.15%via GHSA
CVE-2026-41001Medium· 5.3
3mo ago

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable d…

Sunlitvmware · spring_bootEPSS 0.09%via NVD
CWE-377 vulnerabilities (CVEs) · VulnSea