VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

200 CVEsRSS

CVE-2026-78208High· 7.5
1mo ago

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed i…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-55477High· 7.2
1mo ago

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

▾ Twilightmhsanaei · github.com/mhsanaei/3x-ui/v3EPSS 0.61%via GHSA
GHSA-qp76-pq9f-gr9mHigh· 5.9
1mo ago

Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4

Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4

▾ Twilightnltk · nltkvia GHSA
CVE-2026-62385Medium· 5.9
1mo ago

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attac…

▾ Sunlitnltk · nltkEPSS 0.42%via NVD
CVE-2026-63343Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file o…

▾ MidnightRed HatEPSS 0.48%via NVD
CVE-2026-64679High· 8.1
1mo ago

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted reposi…

▾ Twilightrunatlantis · github.com/runatlantis/atlantisEPSS 0.80%via NVD
CVE-2026-49360High
1mo ago

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL …

▾ Twilightrecce · recceEPSS 1.1%via NVD
CVE-2026-48749Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fi…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48750Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `e…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48752Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command executio…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48753Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary co…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
GHSA-ghvf-qf6h-g8x5High
1mo ago

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

▾ Twilightnocobase · @nocobase/servervia GHSA
CVE-2026-53451Critical· 9.8
1mo ago

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled sn…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-49441Critical· 9.1
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts …

▾ Midnightwazuh · wazuhEPSS 0.77%via NVD
CVE-2026-48162Critical· 9.1
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controll…

▾ Midnightwazuh · wazuhEPSS 0.65%via NVD
GHSA-w672-239g-c3grHigh· 6.5
1mo ago

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Twilightgitpython · gitpythonvia GHSA
CVE-2026-76222High· 8.2
1mo ago

gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
GHSA-cc2g-gq8c-r332High· 7.5
1mo ago

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

▾ Twilightgrok-faf-mcp · grok-faf-mcpvia GHSA
GHSA-j4r7-8ph4-43g3High· 7.5
1mo ago

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightfaf-mcp · faf-mcpvia GHSA
GHSA-rr55-jp92-8wp2High· 7.5
1mo ago

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightclaude-faf-mcp · claude-faf-mcpvia GHSA
CVE-2026-52875None
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the res…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-52872High· 8.8
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-75830High· 7.1
1mo ago

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suff…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-75913Critical· 9.3
1mo ago

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-opt…

▾ Midnightdeepseek-tui · deepseek-tuiEPSS 0.48%via NVD
CVE-2026-48798High· 7.1
1mo ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the r…

▾ TwilightSSH · SSH.NETEPSS 0.42%via NVD
CVE-2026-46345High· 8.4
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does …

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.20%via NVD
CVE-2026-72842Critical· 9.9
1mo ago

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%…

▾ MidnightEPSS 0.62%via NVD
CVE-2026-72841Critical· 9.9
1mo ago

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious …

▾ MidnightEPSS 0.62%via NVD
CVE-2026-45725High
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache fil…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.47%via NVD
CVE-2026-65941High· 8.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

▾ TwilightEPSS 0.68%via NVD
CWE-73 vulnerabilities (CVEs) — page 4 · VulnSea