Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,512 CVEs tagged with CWE-221,265 Critical, 3,936 High, 3,913 Medium, 390 Low, 8 Unrated.

CVE-2026-43872

Published Jun 12, 2026

Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-44171

Published Jun 12, 2026

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6961

Published Jun 12, 2026

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during sh…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3840

Published Jun 12, 2026

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py`…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-11847

Published Jun 12, 2026

The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote attackers to exploit this vulnerabi…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-11846

Published Jun 12, 2026

The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-11844

Published Jun 12, 2026

The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside t…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-47368

Published Jun 12, 2026

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or in…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45171

Published Jun 11, 2026

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an aut…

CVSS 8.7 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-24268

Published Jun 11, 2026

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive u…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-49982

Published Jun 11, 2026

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is byp…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44705

Published Jun 11, 2026

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary…

CVSS 7.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53777

Published Jun 11, 2026

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by su…

CVSS 8.6 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-11816

Published Jun 11, 2026

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_…

CVSS 8.1 · High
evidence mentions
7
Buzz score
40.3
Vendor/product tagsBeta · best-effort

CVE-2026-8464

Published Jun 11, 2026

Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's op…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-40987

Published Jun 11, 2026

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled conten…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-52726

Published Jun 10, 2026

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-49219

Published Jun 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can r…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47712

Published Jun 10, 2026

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) de…

CVSS 3.3 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-46703

Published Jun 10, 2026

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0,…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-42305

Published Jun 10, 2026

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-45380

Published Jun 10, 2026

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, a one-byte off-by-one error in SafeOutPathBuilder::r…

CVSS 3.6 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-0270

Published Jun 10, 2026

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-50567

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Unarchive in…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45569

Published Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Showing 426-450 of 9,512 CVEsPage 18 of 381