CWE-24

CWE-24 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-24, highest CVSS first.

  1. HIGH 8.5CVE-2026-97730

    In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-103088public PoC

    Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler…

    AI risk analysis on Exploit-DB.ai →

  3. LOW 2.5CVE-2026-104994public PoC

    Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraf…

    AI risk analysis on Exploit-DB.ai →