<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Arbitrary File Write (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/arb-write.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/arb-write-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Arbitrary File Write (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45661 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45661</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45661</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file write to remote server filesystems,…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44051 – An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44051</guid>
    <pubDate>Thu, 21 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44051</strong></p>
  <p>An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink creation.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29518 – Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29518</guid>
    <pubDate>Wed, 20 May 2026 13:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29518</strong></p>
  <p>Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitiv…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27891 – FacturaScripts is an open source accounting and invoicing software. Versions 202...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27891</guid>
    <pubDate>Mon, 18 May 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27891</strong></p>
  <p>FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leading to Arbitrary File Write and Remote Code Execution (RCE) by overwriting sensitive .php files outsi…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44852 – An authenticated remote code execution vulnerability exists in the AOS-8 and AOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44852</guid>
    <pubDate>Tue, 12 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44852</strong></p>
  <p>An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-296</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7816 – OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7816</guid>
    <pubDate>Mon, 11 May 2026 16:17:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7816</strong></p>
  <p>OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export.  User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could inject ") TO PROGRAM 'cmd'" to break out of the \copy (...) context and achieve arbitrary command execution on the pgAdmin server, or ") TO '/path'" for arbitrary file write. Add…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40281 – Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40281</guid>
    <pubDate>Wed, 06 May 2026 21:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40281</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink,…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40453 – The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40453</guid>
    <pubDate>Mon, 27 Apr 2026 09:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40453</strong></p>
  <p>The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilt…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40611 – Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40611</guid>
    <pubDate>Tue, 21 Apr 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40611</strong></p>
  <p>Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fix…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40576 – excel-mcp-server is a Model Context Protocol server for Excel file manipulation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40576</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40576</strong></p>
  <p>excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the network can read, write, and overwrite arbitrary files on the host filesystem by supp…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-25714 – Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25714</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-25714</strong></p>
  <p>Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS comma…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40518 – ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40518</guid>
    <pubDate>Fri, 17 Apr 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40518</strong></p>
  <p>ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influence directory creation and write files outside the intended custom-agent directory, potentially achieving arbitrary fil…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0827 – During an internal security assessment, a potential vulnerability was discovered...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0827</guid>
    <pubDate>Wed, 15 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0827</strong></p>
  <p>During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40090 – Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40090</guid>
    <pubDate>Wed, 15 Apr 2026 04:17:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40090</strong></p>
  <p>Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf package inspect sbom and zarf package inspect documentation subcommands. These subcommands output file paths are constructed by joining a user-controlled output directory with the package's Metadata.Name field read directly from the untrusted package's…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35031 – Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35031</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35031</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. This arbitrary file write can be chained into arbitrary file read via .strm files, database extracti…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40157 – PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the rec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40157</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40157</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without validating archive member paths. A .praison bundle containing ../../ entries will write files outside the intended output directory. An attacker who distributes a malicious bundle can overwrite arbitrary files on the victim's filesystem when they r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4351 – The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4351</guid>
    <pubDate>Fri, 10 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4351</strong></p>
  <p>The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` handlers without any authorization check or nonce verification. The `$_GET['snippets'][]` values are passed unsanitized to `Snippet::activate()`/`Snippet:…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33466 – Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33466</guid>
    <pubDate>Wed, 08 Apr 2026 18:26:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33466</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker who can serve a specially crafted archive to Logstash through a compromised or a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39308 – PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39308</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39308</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesystem path derived from the bundle's internal manifest.json before it verifies that the manifest name and version match the HTTP route. A malicious publisher can place ../ traversal sequences in the bundle manifest and cause the registry server to create…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39307 – PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39307</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39307</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python's zipfile.extractall() without verifying if the files within the archive resolve outside of the intended extraction dire…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39306 – PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39306</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39306</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-controlled .praison tar archives with tar.extractall() and does not validate archive member paths before extraction. A malicious publisher can upload a recipe bundle that contains ../ traversal entries and any user who later pulls that recipe will write files outside the output direc…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34838 – Group-Office is an enterprise customer relationship management and groupware too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34838</guid>
    <pubDate>Thu, 02 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34838</strong></p>
  <p>Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directl…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33949 – Tina is a headless content management system. Prior to version 2.2.2, a path tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33949</guid>
    <pubDate>Wed, 01 Apr 2026 17:28:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33949</strong></p>
  <p>Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the ability to replace critical server configuration files and potentially execute…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29870 – A directory traversal vulnerability in the agentic-context-engine project versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29870</guid>
    <pubDate>Tue, 31 Mar 2026 15:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29870</strong></p>
  <p>A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the intended checkpoint directory. This vulnerability allows attackers to overwrite arbitra…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30940 – baserCMS is a website development framework. Prior to version 5.2.3, a path trav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30940</guid>
    <pubDate>Tue, 31 Mar 2026 01:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30940</strong></p>
  <p>baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4415 – Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4415</guid>
    <pubDate>Mon, 30 Mar 2026 08:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4415</strong></p>
  <p>Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15036 – A path traversal vulnerability exists in the `extract_archive_to_dir` function w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15036</guid>
    <pubDate>Mon, 30 Mar 2026 02:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15036</strong></p>
  <p>A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extraction. An attacker with control over the tar.gz file can exploit this issue to overwrite arbitrary file…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33309 – Langflow is a tool for building and deploying AI-powered agents and workflows. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33309</guid>
    <pubDate>Tue, 24 Mar 2026 13:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33309</strong></p>
  <p>Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved. Because the underlying storage layer lacks boundary containment checks, the system relies entirely on the HTTP-layer `Val…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27625 – Stirling-PDF is a locally hosted web application that performs various operation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27625</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27625</strong></p>
  <p>Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markdown/pdf endpoint extracts user-supplied ZIP entries without path checks. Any authenticated user can write files outside the intended temporary working directory, leading to arbitrary file write with the privileges of the Stirling-PDF process user (st…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3029 – A path traversal and arbitrary file write vulnerability exist in the embedded ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3029</guid>
    <pubDate>Thu, 19 Mar 2026 16:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3029</strong></p>
  <p>A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31979 – Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31979</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31979</strong></p>
  <p>Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from the tasks daemon's systemd hardening, exposing it to the host /tmp. A local user can exploit this via sy…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41758 – A low-privileged remote attacker can exploit an arbitrary file write vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41758</guid>
    <pubDate>Mon, 09 Mar 2026 09:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41758</strong></p>
  <p>A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41757 – A low-privileged remote attacker can abuse the backup restore functionality of U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41757</guid>
    <pubDate>Mon, 09 Mar 2026 09:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41757</strong></p>
  <p>A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2743 – Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2743</guid>
    <pubDate>Thu, 05 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2743</strong></p>
  <p>Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT).   This issue affects SeppMail: 15.0.2.1 and before</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27905 – BentoML is a Python library for building online serving systems optimized for AI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27905</guid>
    <pubDate>Tue, 03 Mar 2026 23:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27905</strong></p>
  <p>BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, not the symlink's target. An attacker can create a malicious bento/model tar file containing a sym…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28400 – Docker Model Runner (DMR) is software used to manage, run, and deploy AI models ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28400</guid>
    <pubDate>Fri, 27 Feb 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28400</strong></p>
  <p>Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a  POST `/engines/_configure`  endpoint that accepts arbitrary runtime flags without authentication. These flags are passed directly to the underlying inference server (llama.cpp). By injecting the  --log-file  flag, an attacker with network access to the Model Runner API…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3223 – Arbitrary file write &amp; potential privilege escalation exploiting zip slip vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3223</guid>
    <pubDate>Fri, 27 Feb 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3223</strong></p>
  <p>Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27819 – Vikunja is an open-source self-hosted task management platform. Prior to version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27819</guid>
    <pubDate>Wed, 25 Feb 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27819</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vikunja/vikunja repository fails to sanitize file paths within the provided ZIP archive. A maliciously crafted ZIP can bypass the intended extraction directory to overwrite arbitrary files on the host system. Additionally, we’ve discov…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3179 – The FTP Backup on the ADM does not properly sanitize filenames received from the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3179</guid>
    <pubDate>Wed, 25 Feb 2026 06:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3179</strong></p>
  <p>The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal vulnerability may allow an attacker to overwrite arbitrary files on the system and potentia…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27641 – Flask-Reuploaded provides file uploads for Flask. A critical path traversal and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27641</guid>
    <pubDate>Wed, 25 Feb 2026 04:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27641</strong></p>
  <p>Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27606 – Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27606</guid>
    <pubDate>Wed, 25 Feb 2026 03:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27606</strong></p>
  <p>Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins)…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26359 – Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26359</guid>
    <pubDate>Thu, 19 Feb 2026 09:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26359</strong></p>
  <p>Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61879 – In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61879</guid>
    <pubDate>Thu, 12 Feb 2026 17:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61879</strong></p>
  <p>In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62676 – An Improper Link Resolution Before File Access ('Link Following') vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62676</guid>
    <pubDate>Tue, 10 Feb 2026 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62676</strong></p>
  <p>An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25763 – OpenProject is an open-source, web-based project management software. Prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25763</guid>
    <pubDate>Fri, 06 Feb 2026 22:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25763</strong></p>
  <p>OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest changes” view via git log. By supplying a specially crafted rev value (for example, rev=--output=/tmp/poc.txt), an attacker can inje…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25592 – Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25592</guid>
    <pubDate>Fri, 06 Feb 2026 21:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25592</strong></p>
  <p>Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem has been fixed in Microsoft.SemanticKernel.Core version 1.71.0. As a mitigation, users can create a Function Invocation Filte…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-64712 – The unstructured library provides open-source components for ingesting and pre-p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64712</guid>
    <pubDate>Wed, 04 Feb 2026 18:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-64712</strong></p>
  <p>The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24685 – OpenProject is an open-source, web-based project management software. Versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24685</guid>
    <pubDate>Wed, 28 Jan 2026 17:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24685</strong></p>
  <p>OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s repository diff download endpoint (`/projects/:project_id/repository/diff.diff`) when rendering a single revision via git show. By supplying a specially crafted rev value (for example, `rev=--output=/tmp/poc.txt)`, an attacker can in…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24770 – RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24770</guid>
    <pubDate>Tue, 27 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24770</strong></p>
  <p>RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to Remote Code Execution) via a malicious ZIP archive. The MinerUParser class retrieves and extracts ZIP files from an external source (mineru_server_u…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23954 – Incus is a system container and virtual machine manager. Versions 6.21.0 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23954</guid>
    <pubDate>Thu, 22 Jan 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23954</strong></p>
  <p>Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the h…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47871 – Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47871</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47871</strong></p>
  <p>Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47746 – NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47746</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47746</strong></p>
  <p>NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23746 – Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23746</guid>
    <pubDate>Thu, 15 Jan 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23746</strong></p>
  <p>Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoting channel with unsafe formatter/settings that permit untrusted remoting object invocation. A remote…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22249 – Docmost is an open-source collaborative wiki and documentation software. From 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22249</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22249</strong></p>
  <p>Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability is fixed in 0.24.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-37174 – Authenticated arbitrary file write vulnerability exists in the web-based managem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37174</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-37174</strong></p>
  <p>Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22685 – DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22685</guid>
    <pubDate>Sat, 10 Jan 2026 06:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22685</strong></p>
  <p>DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension installation mechanism. When processing extension packages (NUPKG archives), DevToys does not sufficiently validate file paths contained within the archive. A malicious extension package could include crafted file entries such as ../../…/target-file,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66449 – ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66449</guid>
    <pubDate>Tue, 16 Dec 2025 01:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66449</strong></p>
  <p>ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file.name` directly from user supplied data without doing any sanitization on the name thus allowing for arbitrary file write. This can be used to overwr…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34181 – NetSupport Manager &lt; 14.12.0001 contains an arbitrary file write vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34181</guid>
    <pubDate>Mon, 15 Dec 2025 15:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34181</strong></p>
  <p>NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be leveraged to place attacker-controlled DLLs or executables in privileged paths and achi…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65530 – An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65530</guid>
    <pubDate>Fri, 12 Dec 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65530</strong></p>
  <p>An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34392 – Barracuda Service Center, as implemented in the RMM solution, in versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34392</guid>
    <pubDate>Wed, 10 Dec 2025 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34392</strong></p>
  <p>Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34414 – Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34414</guid>
    <pubDate>Tue, 09 Dec 2025 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34414</strong></p>
  <p>Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel with SOAP and binary formatters configured at TypeFilterLevel=Full and exposes default ObjectURI endpoi…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12422 – Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12422</guid>
    <pubDate>Tue, 28 Oct 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12422</strong></p>
  <p>Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62725 – Docker Compose trusts the path information embedded in remote OCI compose artifa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62725</guid>
    <pubDate>Mon, 27 Oct 2025 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62725</strong></p>
  <p>Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI…</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61035 – The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect defau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61035</guid>
    <pubDate>Wed, 22 Oct 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61035</strong></p>
  <p>The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik file, which is created with mode 0777 and 0775 respectively, exposing secrets to other local users. Additionally, the .kimlik file is written without symlink checks, allowing local attackers to overwrite arbitrary files. This can result in information disclosure…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-37132 – An arbitrary file write vulnerability exists in the web-based management interfa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37132</guid>
    <pubDate>Tue, 14 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-37132</strong></p>
  <p>An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10284 – BBOT's unarchive module could be abused by supplying malicious archives files an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10284</guid>
    <pubDate>Thu, 09 Oct 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10284</strong></p>
  <p>BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11539 – Grafana Image Renderer is vulnerable to remote code execution due to an arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11539</guid>
    <pubDate>Thu, 09 Oct 2025 08:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11539</strong></p>
  <p>Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then loaded by the Chromium process.  Instances are vulnerable if:  1. The default token ("authToken") is not c…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10578 – A potential security vulnerability has been identified in the HP Support Assista...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10578</guid>
    <pubDate>Wed, 01 Oct 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10578</strong></p>
  <p>A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34191 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34191</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34191</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deployments) contain an arbitrary file write vulnerability via the response file handling. When tasks produce output the service writes response data into files under /opt/PrinterInstallerClient/tmp/responses/ reusing the requested filename. The service fol…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-57644 – Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57644</guid>
    <pubDate>Fri, 19 Sep 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-57644</strong></p>
  <p>Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request forgery (SSRF), enabling interaction with internal or external systems. Success…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41714 – The upload endpoint insufficiently validates the 'Upload-Key' request header. By...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41714</guid>
    <pubDate>Wed, 10 Sep 2025 07:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41714</strong></p>
  <p>The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts outside the intended storage location. In certain configurations this enables arbitrary file write and may be leveraged to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58158 – Harness Open Source is an end-to-end developer platform with Source Control Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58158</guid>
    <pubDate>Fri, 29 Aug 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58158</strong></p>
  <p>Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries. Prior to version 3.3.0, Open Source Harness git LFS server (Gitness) exposes api to retrieve and upload files via git LFS. Implementation of upload git LFS file api is vulnerable to arbitrary file write. Due to improper sanitization for u…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54802 – pyLoad is the free and open-source Download Manager written in pure Python. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54802</guid>
    <pubDate>Tue, 05 Aug 2025 01:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54802</strong></p>
  <p>pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in pyLoad-ng CNL Blueprint via package parameter, allowing Arbitrary File Write which leads to Remote Code Execution (RCE). The addcrypted endpoint in pyload-ng suffers from an unsafe path construction vulnerability, allowing unauthenticated a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54386 – Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and belo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54386</guid>
    <pubDate>Sat, 02 Aug 2025 00:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54386</strong></p>
  <p>Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-51480 – Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-51480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-51480</guid>
    <pubDate>Tue, 22 Jul 2025 16:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-51480</strong></p>
  <p>Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54071 – RomM (ROM Manager) allows users to scan, enrich, browse and play their game coll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54071</guid>
    <pubDate>Mon, 21 Jul 2025 20:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54071</strong></p>
  <p>RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta.3 and below, an authenticated arbitrary file write vulnerability exists in the /api/saves endpoint. This can lead to Remote Code Execution on the system. The vulnerability permits arbitrary file write operations, allowing attackers to create or modi…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7619 – BatchSignCS, a background Windows application developed by WellChoose, has an Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7619</guid>
    <pubDate>Mon, 14 Jul 2025 04:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7619</strong></p>
  <p>BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6806 – Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6806</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6806</strong></p>
  <p>Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the implementation of the decryptFile method. The issue results from the lack of proper…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6801 – Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6801</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6801</strong></p>
  <p>Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the implementation of the saveNICParamsToFile method. The issue results from th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43026 – A potential security vulnerability has been identified in the HP Support Assista...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43026</guid>
    <pubDate>Thu, 05 Jun 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43026</strong></p>
  <p>A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4632 – Improper limitation of a pathname to a restricted directory vulnerability in Sam...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4632</guid>
    <pubDate>Tue, 13 May 2025 06:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4632</strong></p>
  <p>Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-46347 – YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46347</guid>
    <pubDate>Tue, 29 Apr 2025 18:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-46347</strong></p>
  <p>YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of the server. This could potentially be performed unwittingly by a user. This issue has been patched in…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23250 – NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23250</guid>
    <pubDate>Tue, 22 Apr 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23250</strong></p>
  <p>NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3294 – The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3294</guid>
    <pubDate>Thu, 17 Apr 2025 06:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3294</strong></p>
  <p>The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may make remote code execution possible assuming the files can be written to by th…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31499 – Jellyfin is an open source self hosted media server. Versions before 10.10.7 are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31499</guid>
    <pubDate>Tue, 15 Apr 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31499</strong></p>
  <p>Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code execution by anyone with credentials to a low-privileged user. This vulnerability was previously reported in CVE-2023-49096 and patched in version 10.8.13, but the patch can be bypassed. The original fix sanitizes some p…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27082 – Arbitrary File Write vulnerabilities exist in the web-based management interface...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27082</guid>
    <pubDate>Tue, 08 Apr 2025 17:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27082</strong></p>
  <p>Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8019 – In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8019</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8019</strong></p>
  <p>In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in s…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7034 – In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7034</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7034</strong></p>
  <p>In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames. The vulnerability arises from the usage of `file_path = f"{UPLOAD_DIR}/{file.filename}"` without proper input validation or sanitization. An attacker can exploit this by manipulating the `file.filename` parameter to include directory traversal seque…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7033 – In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7033</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7033</strong></p>
  <p>In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the application improperly handles file paths, allowing an attacker to manipulate the file path to write files to arbitrary locations on the server's filesystem. This can result in overwriting critical system or application files, causing denial of serv…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-12216 – A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12216</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-12216</strong></p>
  <p>A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from URLs without proper sanitization, making it susceptible to a TarSlip vulnerability. Attackers can exploit this by crafting malicious tar files that, when extracted, can overwrite files on the…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11170 – A vulnerability in danny-avila/librechat version git 81f2936 allows for path tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11170</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11170</strong></p>
  <p>A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10901 – In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/ru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10901</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10901</strong></p>
  <p>In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE) by writing malicious files such as `__i…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10835 – In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run`...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10835</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10835</strong></p>
  <p>In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10834 – eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10834</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10834</strong></p>
  <p>eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolute path to a call to `os.path.join`, enabling an attacker to write files to arbitrary locations on the target server. This vulnerability can be exploited by setting the `doc_file.filename` to an absolute path, which can l…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10833 – eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10833</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10833</strong></p>
  <p>eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27783 – Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27783</guid>
    <pubDate>Wed, 19 Mar 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27783</strong></p>
  <p>Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe deserialization to achieve remote code execution. As of time of publication, no known patches are available.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27782 – Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27782</guid>
    <pubDate>Wed, 19 Mar 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27782</strong></p>
  <p>Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe deserialization to achieve remote code execution. As of time of publication, no known patches are available.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29787 – `zip` is a zip library for rust which supports reading and writing of simple ZIP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29787</guid>
    <pubDate>Mon, 17 Mar 2025 14:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29787</strong></p>
  <p>`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive are allowed to be used for later files in the archive without validation of the final canonicalized path, allowing maliciously crafted archives…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23360 – NVIDIA Nemo Framework contains a vulnerability where a user could cause a relati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23360</guid>
    <pubDate>Tue, 11 Mar 2025 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23360</strong></p>
  <p>NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25761 – HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25761</guid>
    <pubDate>Thu, 27 Feb 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25761</strong></p>
  <p>HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25761">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
