VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

200 CVEsRSS

CVE-2026-59819Medium· 4.9
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, a…

▾ Sunlitlitellm · litellmEPSS 0.57%via NVD
CVE-2026-45016Medium· 6.5
2mo ago

EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose

EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose

▾ Sunlitegroupware · egroupware/egroupwarevia GHSA
CVE-2026-8921High· 8.5
2mo ago

External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' sect…

External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' sect…

▾ TwilightASUS · ASUS Business ManagerEPSS 0.15%via NVD
CVE-2026-58293High· 8.1
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via CVEORG
CVE-2026-9559Critical· 9.9
2mo ago

Mautic vulnerable to Path Traversal via Campaign Import

Mautic vulnerable to Path Traversal via Campaign Import

▾ Midnightmautic · mautic/coreEPSS 0.93%via GHSA
CVE-2026-50162Medium· 5.3
2mo ago

oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)

A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…

▾ SunlitRed Hat · Red Hat Edge Manager 1.1EPSS 0.51%via CSAF
GHSA-2wwr-9x6f-88gpMedium· 5.3
2mo ago

EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components

EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components

▾ Sunliteasycorp · easycorp/easyadmin-bundlevia GHSA
GHSA-fr4h-3cph-29xvHigh· 7.1
3mo ago

pnpm: Hoisted install imports lockfile alias outside node_modules

pnpm: Hoisted install imports lockfile alias outside node_modules

▾ Twilightpnpm · pnpmvia GHSA
GHSA-72r4-9c5j-mj57High· 7.1
3mo ago

pnpm: `patch-remove` could delete project-selected files outside the patches directory

pnpm: `patch-remove` could delete project-selected files outside the patches directory

▾ Twilightpnpm · pnpmvia GHSA
CVE-2026-47214High· 7.1
3mo ago

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.

▾ Twilightdocling · doclingEPSS 0.37%via NVD
CVE-2026-49358Low· 3.0
3mo ago

PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles

PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles

▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.15%via GHSA
CVE-2026-55699Medium· 6.5
3mo ago

pnpm: Reserved bin name deletes PNPM_HOME during global remove

pnpm: Reserved bin name deletes PNPM_HOME during global remove

▾ Sunlitpnpm · pnpmEPSS 0.45%via GHSA
CVE-2026-55700High· 7.1
3mo ago

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

▾ Twilightpnpm · pnpmEPSS 0.42%via GHSA
CVE-2025-71338Critical· 10.0PoC
3mo ago

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the stor…

▾ Abyssalflowiseai · flowiseEPSS 1.2%via NVD
CVE-2026-54134High
3mo ago

OctoPrint has possible file exfiltration via query parameters on upload endpoints

OctoPrint has possible file exfiltration via query parameters on upload endpoints

▾ TwilightOctoPrint · OctoPrintEPSS 0.32%via GHSA
GHSA-2h46-9x5w-4wf7Medium
3mo ago

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

▾ Sunlitentireio · github.com/entireio/clivia GHSA
GHSA-2fmp-9rvw-hc96High· 7.1
3mo ago

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

▾ Twilightnetwork-ai · network-aivia GHSA
GHSA-f44v-7qgw-9gh9High· 8.1
3mo ago

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-p6gq-j5cr-w38fHigh· 7.1
3mo ago

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

▾ Twilightnodemailer · nodemailervia GHSA
CVE-2026-12568Medium· 6.5
3mo ago

BBOT: Arbitrary File Write in postman_download Module

BBOT: Arbitrary File Write in postman_download Module

▾ Sunlitbbot · bbotEPSS 0.25%via GHSA
CVE-2026-11752Medium
3mo ago

Armeria: External Control of File Name or Path in xDS SDS DataSource

Armeria: External Control of File Name or Path in xDS SDS DataSource

▾ Sunlitlinecorp · com.linecorp.armeria:armeria-xdsEPSS 0.32%via GHSA
CVE-2026-2604Medium· 5.6PoC
3mo ago

A flaw was found in evolution-data-server

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored…

▾ TwilightGNOME · Evolution Data ServerEPSS 0.28%via NVD
CVE-2026-48520Medium· 6.1
3mo ago

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

▾ Sunlitlangflow · langflowEPSS 0.44%via GHSA
CVE-2026-53632Medium
3mo ago

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

▾ Sunlitlaunch-editor · launch-editorEPSS 0.41%via GHSA
CVE-2025-52465High· 7.2
3mo ago

GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page

GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page

▾ Twilightgeoserver · org.geoserver.web:gs-web-appEPSS 0.62%via GHSA
CVE-2026-47643Critical· 9.8
3mo ago

Azure Stack Edge Remote Code Execution Vulnerability

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Azure Stack EdgeEPSS 0.97%via CVEORG
CVE-2026-35080High· 8.1
3mo ago

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.53%via NVD
CVE-2026-35079High· 8.1
3mo ago

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.53%via NVD
CVE-2026-35078High· 8.1
3mo ago

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.53%via NVD
CVE-2026-35077High· 8.1
3mo ago

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.53%via NVD
CWE-73 vulnerabilities (CVEs) — page 6 · VulnSea