VulnSea

CWE-610

CVEs classified under CWE-610, newest first.

6 CVEsRSS

CVE-2026-19032Medium· 5.3
2w ago

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(…

SunlitEPSS 0.46%via NVD
CVE-2026-55389High· 7.5
1mo ago

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.43%via OSV
CVE-2026-55390High· 7.5
1mo ago

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.36%via GHSA
CVE-2026-30817Medium· 5.7
5mo ago

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may a…

Sunlittp-link · archer_ax53_firmwareEPSS 0.34%via NVD
CVE-2026-30816Medium· 5.7
5mo ago

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may…

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may…

Sunlittp-link · archer_ax53_firmwareEPSS 0.29%via NVD
CVE-2022-24241High· 7.5
4y ago

ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.

ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.

Twilightaceware · aceweb_online_portalEPSS 0.94%via NVD
CWE-610 vulnerabilities (CVEs) · VulnSea