Skip to main content

CWE archive

CWE-41 CVEs

Programmatic archive

28 CVEs tagged with CWE-410 Critical, 8 High, 18 Medium, 2 Low, 0 Unrated.

CVE-2026-66064

Published Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-49401

Published Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50568

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFile…

CVSS 3.6 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-5816

Published Apr 22, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute…

CVSS 8.0 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-34510

Published Apr 1, 2026

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Att…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-34451

Published Mar 31, 2026

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesys…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-58290

Published Oct 11, 2025

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43298

Published Sep 15, 2025

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An ap…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8765

Published Mar 20, 2025

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' an…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6839

Published Mar 20, 2025

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching pat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0115

Published Mar 12, 2025

A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the m…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-24470

Published Feb 11, 2025

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-45405

Published Sep 6, 2024

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` t…

CVSS 6.0 · Medium
Showing 1-25 of 28 CVEsPage 1 of 2