Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,511 CVEs tagged with CWE-221,265 Critical, 3,936 High, 3,912 Medium, 390 Low, 8 Unrated.

CVE-2026-54066

Published Jun 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53766

Published Jun 24, 2026

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces work…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52811

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-52797

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together w…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31978

Published Jun 24, 2026

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-49247

Published Jun 24, 2026

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49246

Published Jun 24, 2026

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing path sa…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-48789

Published Jun 24, 2026

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listin…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44022

Published Jun 24, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handlin…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-44017

Published Jun 24, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download function…

CVSS 7.5 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-55488

Published Jun 24, 2026

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an a…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57296

Published Jun 24, 2026

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allow…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47385

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create permission can attach a SQLite source pointing at an arbitrar…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48020

Published Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an…

CVSS 7.8 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-54319

Published Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54014

Published Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a path traversal vulnerability exists in open-webui's cache file…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52844

Published Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49406

Published Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49465

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42867

Published Jun 23, 2026

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/kn…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-11940

Published Jun 23, 2026

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itsel…

CVSS 7.8 · High
evidence mentions
8
Buzz score
32.0

CVE-2026-56258

Published Jun 23, 2026

Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-55443

Published Jun 22, 2026

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-54293

Published Jun 22, 2026

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.1…

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-53779

Published Jun 22, 2026

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by s…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4
Showing 326-350 of 9,511 CVEsPage 14 of 381