CWE-73
CWE-73 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-73, highest CVSS first.
- HIGH 8.8CVE-2026-60009public PoC
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, …
theia
- HIGH 8.8CVE-2026-15307public PoC
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lo…
- HIGH 7.1CVE-2026-18806
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.