VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

200 CVEsRSS

CVE-2026-65939Medium· 6.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

▾ SunlitEPSS 0.38%via NVD
CVE-2026-72742High· 8.6
1mo ago

DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the u…

DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the u…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-19353Medium· 5.0
1mo ago

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can …

▾ SunlitEPSS 0.38%via NVD
CVE-2026-76217Medium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Sunlitgitpython · gitpythonEPSS 0.41%via OSV
GHSA-hh9p-6wh2-4mfcMedium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ SunlitGitPython · GitPythonvia GHSA
GHSA-hmq2-w58f-27jcHigh· 8.2
1mo ago

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-66310High· 7.7
1mo ago

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

▾ Twilightmicrosoft · edgeEPSS 0.36%via NVD
CVE-2026-18806High· 7.1
1mo ago

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.

▾ TwilightEPSS 0.15%via NVD
GHSA-88pr-878c-24wfHigh
1mo ago

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

▾ Twilightflowise-components · flowise-componentsvia GHSA
CVE-2026-65802High· 7.4
1mo ago

Microsoft Edge for Android Information Disclosure Vulnerability

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.92%via CVEORG
GHSA-3f7w-8rr8-f37fHigh· 8.1
1mo ago

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-539m-9xh6-q6rrMedium· 6.5
1mo ago

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

▾ SunlitGitPython · GitPythonvia GHSA
CVE-2026-64816Medium· 6.5
1mo ago

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-67429Critical· 10.0
1mo ago

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

▾ Midnightflyto-core · flyto-coreEPSS 0.77%via GHSA
GHSA-68r5-9hpg-7qw9Critical· 9.4
2mo ago

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-dsml-servletvia GHSA
CVE-2026-55628Medium· 6.1
2mo ago

ImageMagick: Policy Bypass in concatenate operation due to missing checks

ImageMagick: Policy Bypass in concatenate operation due to missing checks

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.14%via GHSA
CVE-2026-65896High· 7.1
2mo ago

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), …

▾ TwilightEPSS 0.48%via NVD
GHSA-xmc9-4f2h-jf9cHigh
2mo ago

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

▾ Twilightn8n · n8nvia GHSA
CVE-2026-58420Medium
2mo ago

Gitea: Local File Inclusion via file:// URI in Migration Restore

Gitea: Local File Inclusion via file:// URI in Migration Restore

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-46336High· 7.1
2mo ago

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated users can rename uploaded files with path traversal sequences b…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-55002High· 8.8
2mo ago

Microsoft SQL Server Elevation of Privilege Vulnerability

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SQL Server 2016 Service Pack 3 (GDR)EPSS 0.91%via CVEORG
CVE-2026-54108Medium· 6.5
2mo ago

Microsoft SharePoint Server Spoofing Vulnerability

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 1.1%via CVEORG
CVE-2026-50462High· 7.8
2mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.46%via CVEORG
CVE-2026-61462High· 8.6PoC
2mo ago

mcp-gitlab Path Traversal via job_id Parameter

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to e…

▾ Midnightzereight · mcp-gitlabEPSS 0.51%via CVEORG
CVE-2026-13014None
2mo ago

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, c…

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, c…

▾ SunlitEPSS 0.70%via NVD
CVE-2026-15540Medium· 4.3
2mo ago

A vulnerability was detected in SourceCodester Online Book Store System 1.0

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument pa…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-53449Medium· 6.0
2mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated a…

▾ Sunlitcoturn_project · coturnEPSS 0.21%via NVD
CVE-2026-14480Critical· 9.9
2mo ago

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database fi…

▾ MidnightEPSS 0.62%via NVD
GHSA-wm45-qh3g-v83fHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary server-side file read via attachment upload

mcp-atlassian: Arbitrary server-side file read via attachment upload

▾ Twilightmcp-atlassian · mcp-atlassianvia OSV
GHSA-52vm-mxx8-f227High· 7.7
2mo ago

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

▾ Twilightphantom-audio · phantom-audiovia GHSA
CWE-73 vulnerabilities (CVEs) — page 5 · VulnSea