Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,512 CVEs tagged with CWE-221,265 Critical, 3,936 High, 3,913 Medium, 390 Low, 8 Unrated.

CVE-2026-8811

Published Jun 18, 2026

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the inten…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48768

Published Jun 18, 2026

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to con…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-12568

Published Jun 17, 2026

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name cont…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12565

Published Jun 17, 2026

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48820

Published Jun 17, 2026

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_g…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49133

Published Jun 17, 2026

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directo…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-55201

Published Jun 17, 2026

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to…

CVSS 7.4 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-53872

Published Jun 17, 2026

picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by chaining io.FileIO and urllib…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-54193

Published Jun 17, 2026

Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.

CVSS 7.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-52716

Published Jun 17, 2026

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-69128

Published Jun 17, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a throug…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9690

Published Jun 17, 2026

Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-50203

Published Jun 17, 2026

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the con…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-48055

Published Jun 17, 2026

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in S…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47277

Published Jun 17, 2026

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an una…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-40724

Published Jun 17, 2026

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-27400

Published Jun 17, 2026

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-22334

Published Jun 17, 2026

Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10094

Published Jun 17, 2026

A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitra…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-69139

Published Jun 17, 2026

Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69131

Published Jun 17, 2026

Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-60223

Published Jun 17, 2026

Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.

CVSS 7.7 · High

CVE-2024-32729

Published Jun 17, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue af…

CVSS 7.5 · High

CVE-2026-48776

Published Jun 17, 2026

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsaf…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 376-400 of 9,512 CVEsPage 16 of 381