CVE-2025-46822
OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.
- Affected products
- Java-Springboot-Codebase
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- EPSS
- 4.1% (90th percentile)
- Weakness
- CWE-36
- NVD status
- Deferred
- Published
- 2025-05-21
CVE-2025-46822 at NVD
27 known exploits for CVE-2025-46822
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Use After Free in Microsoft
Exploit for Link Following in Microsoft
Exploit for Protection Mechanism Failure in Microsoft
Exploit for Improper Input Validation in Openprinting Cups
Exploit for Improper Authentication in Openprinting Cups
Exploit for OS Command Injection in Openhands
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Code Injection in N8N
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Wavlink Wl-Nu516U1_Firmware
Exploit for CVE-2026-16723
Exploit for Improper Authorization in Microsoft
Exploit for Command Injection in Microsoft
Exploit for Deserialization of Untrusted Data in Microsoft
Exploit for CVE-2026-53359
Exploit for Improper Authentication in Oracle E-Business_Suite
Exploit for CVE-2026-46331
Exploit for Code Injection in Lantronix Eds5032_Firmware
Exploit for Path Traversal in Fortinet Fortisandbox
Exploit for OS Command Injection in Fortinet Fortisandbox
Exploit for OS Command Injection in Cisco Nx-Os
Exploit for Improper Restriction of Names for Files and Other Resources in Microsoft
Exploit for UNIX Symbolic Link Following in Litespeedtech Litespeed_Cpanel_Plugin
Exploit for CVE-2026-20262
Exploit for CVE-2025-46822
π Java-springboot-codebase 1.1 Arbitrary File Read
Java-springboot-codebase 1.1 - Arbitrary File Read
Exploit for CVE-2025-46822