VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

180 CVEsRSS

CVE-2026-86751High· 8.5PoC
1w ago

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkou…

Midnightsnipeitapp · snipe-itEPSS 0.26%via NVD
CVE-2026-86741High· 8.5PoC
1w ago

Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails

Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to …

Midnightsnipeitapp · snipe-itEPSS 0.24%via NVD
CVE-2026-53956Medium· 5.4
1w ago

Rattler vulnerable to package cache path traversal via conda package build string

Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…

Sunlitconda · rattler_cacheEPSS 0.24%via CVEORG
CVE-2026-53581Critical· 9.0PoC
1w ago

OPNsense is a FreeBSD based firewall and routing platform

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite a…

Abyssalopnsense · coreEPSS 0.33%via NVD
CVE-2026-86995Medium· 4.3
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration with…

Sunlitn8n · n8nEPSS 0.28%via NVD
GHSA-8m3c-c648-2xjjMedium· 5.9
1w ago

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

Sunlitnodemailer · nodemailervia GHSA
GHSA-2q42-4q24-7rgvHigh· 7.1
1w ago

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

Twilighttypespec · @typespec/openapi3via GHSA
CVE-2026-78620Medium· 5.9
1w ago

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files b…

SunlitOkta · Okta Access GatewayEPSS 0.25%via NVD
CVE-2026-66302Critical· 9.8
1w ago

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · skype_for_business_serverEPSS 0.53%via NVD
CVE-2026-69805High· 7.5
1w ago

External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.

External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · Microsoft Visual Studio 2022 version 17.14EPSS 0.51%via NVD
CVE-2026-69383High· 7.0
1w ago

External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.

External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 11 version 23H2EPSS 0.25%via NVD
CVE-2026-69355High· 8.8
1w ago

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.84%via NVD
CVE-2026-62804High· 7.8
1w ago

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Twilightmicrosoft · 365_appsEPSS 0.33%via NVD
CVE-2026-78677High· 7.5
1w ago

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside …

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

Twilightgitpython · gitpythonEPSS 0.43%via OSV
CVE-2026-81830Medium· 5.6
2w ago

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

SunlitOpenVPN · OpenVPNEPSS 0.11%via NVD
CVE-2026-86189Critical· 9.8
2w ago

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers ca…

MidnightWWBN · AVideoEPSS 0.41%via NVD
CVE-2026-85687High· 7.5
2w ago

surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters

surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying…

TwilightEPSS 0.29%via NVD
CVE-2026-80119High· 7.8
2w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to d…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to d…

TwilightEPSS 0.13%via NVD
CVE-2026-80118High· 7.1PoC
2w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

MidnightPassMark Software · PerformanceTestEPSS 0.11%via NVD
CVE-2026-85603Medium· 6.5
2w ago

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply direct…

Sunlitgetgrav · gravEPSS 0.40%via NVD
CVE-2026-82194Medium· 5.5
2w ago

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files…

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files…

SunlitEPSS 0.20%via NVD
CVE-2026-81347Medium· 5.9
2w ago

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files ou…

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files ou…

SunlitEPSS 0.23%via NVD
CVE-2026-79426High· 7.2PoC
2w ago

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

MidnightEPSS 0.29%via NVD
CVE-2026-85684Critical· 9.1PoC
2w ago

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequence…

Abyssaldatalab-to · markerEPSS 0.66%via NVD
CVE-2026-85176High· 8.8
2w ago

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and…

Twilightdbgate · dbgateEPSS 0.34%via NVD
CVE-2026-85160High· 8.1
2w ago

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter conca…

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter conca…

TwilightEPSS 0.21%via NVD
CVE-2026-75602Medium· 6.5
2w ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a pe…

SunlitOpenListTeam · github.com/OpenListTeam/OpenListEPSS 0.43%via NVD
CVE-2026-84374High· 7.5
2w ago

Laravel Excel provides supercharged Excel exports and imports in Laravel

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::…

Twilightmaatwebsite · maatwebsite/excelEPSS 0.57%via NVD
CVE-2026-84478High· 7.3
2w ago

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers c…

TwilightEPSS 0.36%via NVD
GHSA-2rx9-3g3h-c2jvHigh· 7.1
2w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

Twilightpnpm · pnpmvia GHSA
CWE-73 vulnerabilities (CVEs) — page 2 · VulnSea