VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

179 CVEsRSS

CVE-2026-53940High· 8.8
today

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

Twilightconda · condavia NVD
CVE-2026-54584Medium· 5.3
today

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport …

SunlitMidnightBSD · mportvia NVD
CVE-2026-94401High· 8.3
today

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

TwilightMISP · MISPvia NVD
CVE-2026-90817Critical· 9.8PoC
yesterday

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

AbyssalVanderbilt University · REDCapEPSS 0.57%via NVD
CVE-2026-93987Low· 3.4
2d ago

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the a…

Sunlitrclone · rcloneEPSS 0.10%via NVD
CVE-2026-19860Medium· 5.5
2d ago

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion func…

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion func…

SunlitEPSS 0.23%via NVD
CVE-2026-6205High· 8.1
3d ago

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and c…

An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and c…

TwilightSynology · DiskStation Manager (DSM)EPSS 0.32%via NVD
CVE-2026-54583High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index d…

TwilightMidnightBSD · mportEPSS 0.52%via NVD
CVE-2026-54582Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/in…

SunlitMidnightBSD · mportEPSS 0.53%via NVD
CVE-2026-55062High· 8.4
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

Twilightuniget-org · cliEPSS 0.13%via NVD
CVE-2026-50158High· 7.7
4d ago

yutu is an AI-powered toolkit for managing and growing YouTube channels

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg…

Twilighteat-pray-ai · yutuEPSS 0.17%via NVD
CVE-2026-92595Medium· 5.9PoC
5d ago

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

Twilightnodemailer · nodemailerEPSS 0.19%via NVD
CVE-2026-63225Medium· 4.4
5d ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…

SunlitRedocly · redocly-cliEPSS 0.17%via NVD
CVE-2026-73171High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite …

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite …

TwilightAdvantech · EKI-1242IEIMSEPSS 0.50%via NVD
CVE-2026-76553Medium· 6.5
5d ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP …

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP …

SunlitEPSS 0.42%via NVD
CVE-2026-76796Medium· 4.0
6d ago

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outsi…

The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outsi…

SunlitNewell Brands · DYMO Connect DesktopEPSS 0.24%via NVD
CVE-2026-73496High· 7.7PoC
1w ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src…

Midnightsooperset · mcp-atlassianEPSS 0.33%via NVD
CVE-2026-16338Critical· 9.9
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

MidnightIBM · DataStage on Cloud Pak for DataEPSS 0.61%via NVD
CVE-2026-90946High· 7.5PoC
1w ago

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary director…

MidnightAsyncFuncAI · deepwiki-openEPSS 0.57%via NVD
CVE-2026-90932High· 7.2PoC
1w ago

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file…

Midnightlaradashboard · laradashboardEPSS 0.46%via NVD
CVE-2026-54629High· 7.5
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

Abyssaljulien040 · anyqueryEPSS 0.77%via NVD
CVE-2026-77006Critical· 9.6
1w ago

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user…

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user…

MidnightEPSS 0.18%via NVD
CVE-2026-77005Critical· 9.6
1w ago

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a s…

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a s…

MidnightEPSS 0.30%via NVD
CVE-2026-88899Critical· 9.8PoC
1w ago

knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project roo…

Abyssalknowns-dev · knownsEPSS 0.44%via CVEORG
GHSA-wfgq-w7cq-qj7jHigh· 7.2
1w ago

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

Twilightmistralrs-server-core · mistralrs-server-corevia GHSA
CVE-2026-49836Medium· 4.6PoC
1w ago

psd-tools: arbitrary file write via smart-object filename

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

Twilightpsd-tools · psd-toolsEPSS 0.16%via CVEORG
CVE-2026-87815High· 8.7PoC
1w ago

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbit…

Midnightsiyuan-note · siyuanEPSS 0.27%via NVD
CVE-2026-79692High· 7.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentia…

Twilightdell · secure_connect_gatewayEPSS 0.26%via NVD
CVE-2026-86751High· 8.5PoC
1w ago

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkou…

Midnightsnipeitapp · snipe-itEPSS 0.26%via NVD
CWE-73 vulnerabilities (CVEs) · VulnSea