VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

200 CVEsRSS

CVE-2026-80119High· 7.8
3w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to d…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to d…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-80118High· 7.1PoC
3w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users thr…

▾ MidnightPassMark Software · PerformanceTestEPSS 0.17%via NVD
CVE-2026-85603Medium· 6.5
3w ago

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply direct…

▾ Sunlitgetgrav · gravEPSS 0.63%via NVD
CVE-2026-82194Medium· 5.5
3w ago

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files…

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-81347Medium· 5.9
3w ago

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files ou…

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files ou…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-79426High· 7.2PoC
3w ago

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

▾ MidnightEPSS 0.53%via NVD
CVE-2026-85684Critical· 9.1PoC
3w ago

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter

marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequence…

▾ Abyssaldatalab-to · markerEPSS 1.1%via NVD
CVE-2026-85176High· 8.8
3w ago

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and…

▾ Twilightdbgate · dbgateEPSS 0.63%via NVD
CVE-2026-85160High· 8.1
3w ago

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter conca…

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter conca…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-75602Medium· 6.5
3w ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a pe…

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenListEPSS 0.69%via NVD
CVE-2026-84374High· 7.5
3w ago

Laravel Excel provides supercharged Excel exports and imports in Laravel

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::…

▾ Twilightmaatwebsite · maatwebsite/excelEPSS 0.84%via NVD
CVE-2026-84478High· 7.3
3w ago

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers c…

▾ TwilightEPSS 0.56%via NVD
GHSA-2rx9-3g3h-c2jvHigh· 7.1
3w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

▾ Twilightpnpm · pnpmvia GHSA
CVE-2026-82659High· 7.1
3w ago

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href pr…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.35%via NVD
CVE-2026-82393High· 7.5
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-53508Medium
3w ago

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRef…

▾ Sunlitoasdiff · github.com/oasdiff/oasdiffEPSS 0.50%via NVD
CVE-2026-82637Medium· 5.3PoC
4w ago

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_pat…

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_pat…

▾ Twilightbrowser-use · web-uiEPSS 0.41%via NVD
CVE-2026-66324Medium· 6.5
1mo ago

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.92%via NVD
CVE-2026-53580High· 8.1
1mo ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, all…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-81726High· 8.7
1mo ago

nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)

A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.34%via CSAF
CVE-2026-81727High· 7.1
1mo ago

nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)

A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installa…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.19%via CSAF
CVE-2026-62865None
1mo ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebo…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-56705Critical· 9.8PoC
1mo ago

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP…

▾ AbyssalEPSS 0.90%via NVD
CVE-2026-34967Medium· 5.4
1mo ago

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter …

▾ SunlitEPSS 0.33%via NVD
GHSA-6rj2-96f5-chj9High· 6.5
1mo ago

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-78679Medium· 6.5
1mo ago

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via NVD
GHSA-crmc-f4m7-33fjHigh· 8.4
1mo ago

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonvia GHSA
CVE-2026-79674High· 7.5
1mo ago

nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)

A flaw was found in NLTK. A path traversal vulnerability in corpus-reader constructors allows a remote attacker to bypass the intended data root sandbox. By supplying arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.39%via CSAF
CVE-2026-55609High· 7.1
1mo ago

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools …

▾ Twilightconsciousness-explorer · consciousness-explorerEPSS 0.17%via NVD
CVE-2026-55527High· 7.1
1mo ago

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.48%via OSV
CWE-73 vulnerabilities (CVEs) — page 3 · VulnSea