← Back to feed Search feed

CWE-22 Path Traversal vulnerabilities

100 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-67429Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fiCRITICAL10.040%ileNVD2026-07-29
CVE-2026-59310VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access CRITICAL9.864%ileNVD2026-07-30
CVE-2026-15435IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to tCRITICAL9.851%ileNVD2026-07-30
CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporaryCRITICAL9.843%ileNVD2026-07-30
CVE-2026-14973IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's sCRITICAL9.337%ileNVD2026-07-28
CVE-2026-69110OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackerCRITICAL9.3NVD2026-08-04
CVE-2026-65889Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allowCRITICAL9.225%ileNVD2026-07-29
CVE-2026-65886Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unautCRITICAL9.229%ileNVD2026-07-29
CVE-2026-3141The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability checCRITICAL9.138%ileNVD2026-08-01
CVE-2026-58072A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can leadCRITICAL9.0NVD2026-08-04
CVE-2025-69194Wget2: arbitrary file write via metalink path traversal in gnu wget2HIGH8.850%ileMicrosoft2026-01-13
CVE-2025-47273setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File WriteHIGH8.871%ileMicrosoft2025-05-13
CVE-2025-51480Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwritHIGH8.844%ileMicrosoft2025-07-08
CVE-2026-55100hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenatHIGH8.731%ileNVD2026-07-31
CVE-2026-53502Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded pathHIGH8.728%ileNVD2026-07-31
CVE-2026-69089Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $imageHIGH8.730%ileNVD2026-08-03
CVE-2026-69095OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in HIGH8.746%ileNVD2026-08-03
CVE-2026-67200Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitraryHIGH8.7NVD2026-08-04
CVE-2026-54650openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publHIGH8.629%ileNVD2026-07-28
CVE-2026-11974The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in HIGH8.639%ileNVD2026-07-29
CVE-2026-66415Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated aHIGH8.421%ileNVD2026-07-30
CVE-2026-58177The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This isHIGH8.343%ileNVD2026-07-29
CVE-2026-69086SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,HIGH8.328%ileNVD2026-08-03
CVE-2026-62391The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontendHIGH8.133%ileNVD2026-07-31
CVE-2026-15450The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path travHIGH8.130%ileNVD2026-08-01
CVE-2026-11816Path Traversal in keras-team/kerasHIGH8.144%ileMicrosoft2026-06-09
CVE-2026-6540Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URHIGH7.930%ileNVD2026-07-30
CVE-2026-48374Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability thHIGH7.89%ileNVD2026-07-28
CVE-2026-67309Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX providerHIGH7.840%ileNVD2026-08-01
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesHIGH7.723%ileGitHub2026-07-31
CVE-2026-15280IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segmHIGH7.526%ileNVD2026-07-28
CVE-2026-55389datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.529%ileNVD2026-07-28
CVE-2026-55390datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsHIGH7.529%ileNVD2026-07-28
CVE-2026-5487DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloHIGH7.572%ileNVD2026-07-29
CVE-2026-5491DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloHIGH7.572%ileNVD2026-07-29
CVE-2026-14519IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to rHIGH7.546%ileNVD2026-07-30
CVE-2026-62663Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filtHIGH7.526%ileNVD2026-07-30
CVE-2026-12942IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker cHIGH7.534%ileNVD2026-07-30
CVE-2026-56671ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previHIGH7.548%ileNVD2026-07-31
CVE-2026-56673ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_pathHIGH7.535%ileNVD2026-07-31
CVE-2026-63222CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument usHIGH7.537%ileNVD2026-07-31
CVE-2026-62999Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-direcHIGH7.522%ileNVD2026-07-31
CVE-2026-15006The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnHIGH7.554%ileNVD2026-08-01
CVE-2026-13339The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1HIGH7.547%ileNVD2026-08-02
CVE-2026-18352The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, HIGH7.549%ileNVD2026-08-02
CVE-2026-61372Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. ThiHIGH7.531%ileNVD2026-08-03
CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configurHIGH7.529%ileNVD2026-08-04
CVE-2026-12072Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pHIGH7.5GitHub2026-07-31
CVE-2026-12074Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, HIGH7.5GitHub2026-07-31
CVE-2026-14818A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versiHIGH7.229%ileNVD2026-08-04
CVE-2026-18192VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to eHIGH7.131%ileNVD2026-07-29
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlleHIGH7.121%ileNVD2026-07-30
CVE-2026-9856A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes viHIGH7.122%ileNVD2026-08-02
CVE-2026-54545@wakaru/cli arbitrary file write during bundle unpackHIGH7.15%ileGitHub2026-07-28
CVE-2026-40024Sleuth Kit tsk_recover Path TraversalHIGH7.16%ileMicrosoft2026-04-14
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlledHIGH7.011%ileNVD2026-07-30
CVE-2026-54659Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18MEDIUM6.930%ileNVD2026-07-28
CVE-2026-44943An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remMEDIUM6.926%ileNVD2026-07-29
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controMEDIUM6.924%ileNVD2026-07-30
CVE-2026-66063goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.MEDIUM6.514%ileNVD2026-07-28
CVE-2026-13723A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrarMEDIUM6.525%ileNVD2026-07-29
CVE-2026-5492DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloMEDIUM6.573%ileNVD2026-07-29
CVE-2026-44615Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wiMEDIUM6.540%ileNVD2026-07-31
CVE-2026-9335A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to impropMEDIUM6.547%ileNVD2026-08-02
CVE-2026-14194Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and InforMEDIUM6.536%ileNVD2026-08-04
CVE-2026-34978OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering ofMEDIUM6.533%ileMicrosoft2026-04-14
CVE-2026-69153PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract MEDIUM6.328%ileNVD2026-08-03
CVE-2026-54785gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 untiMEDIUM6.25%ileNVD2026-07-31
CVE-2026-50558Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix dMEDIUM5.916%ileNVD2026-07-29
CVE-2026-66755Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.MEDIUM5.96%ileNVD2026-07-30
CVE-2026-18646A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /systemMEDIUM5.542%ileNVD2026-08-03
CVE-2026-64400ksmbd: prevent path traversal bypass by restricting caseless retryMEDIUM5.528%ileMicrosoft2026-07-14
CVE-2026-5489DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloMEDIUM5.367%ileNVD2026-07-29
CVE-2026-16531An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a MEDIUM5.328%ileNVD2026-07-30
CVE-2026-67295FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers toMEDIUM5.316%ileNVD2026-08-01
CVE-2026-5114The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and MEDIUM4.927%ileNVD2026-07-28
CVE-2026-15601The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (ZiMEDIUM4.952%ileNVD2026-08-01
CVE-2026-17614A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getCoMEDIUM4.455%ileNVD2026-08-04
CVE-2026-55495Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WMEDIUM4.330%ileNVD2026-07-31
CVE-2026-35177Path traversal issue with zip.vim in VimMEDIUM4.13%ileMicrosoft2026-04-14
CVE-2025-53906Vim has path traversal issue with zip.vim and special crafted zip archivesMEDIUM4.151%ileMicrosoft2025-07-08
CVE-2026-55825Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can LOW3.111%ileNVD2026-07-31
CVE-2026-18644A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /LOW2.130%ileNVD2026-08-03
CVE-2026-18645A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sysLOW2.135%ileNVD2026-08-03
CVE-2026-18648A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDatLOW1.97%ileNVD2026-08-03
GHSA-pmwx-rm49-xv39ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversalLOWGitHub2026-07-29
CVE-2026-67970Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive coUNKNOWN4%ileNVD2026-08-03
CVE-2026-34591Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File WriteUNKNOWN38%ileMicrosoft2026-04-14
CVE-2026-32147SFTP chroot bypass via path traversal in SSH_FXP_FSETSTATUNKNOWN28%ileMicrosoft2026-04-14
CVE-2026-41205Mako: Path traversal via double-slash URI prefix in TemplateLookupUNKNOWN29%ileMicrosoft2026-04-14
CVE-2026-41140Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4UNKNOWN22%ileMicrosoft2026-04-14
CVE-2026-44307Mako: Path traversal via backslash URI on Windows in TemplateLookupUNKNOWN46%ileMicrosoft2026-05-12
CVE-2025-59825astral-tokio-tar has a path traversal in tar extractionUNKNOWN10%ileMicrosoft2025-09-09
CVE-2026-7774tarfile.data_filter path traversal bypass allows writing outside the extraction directoryUNKNOWN45%ileMicrosoft2026-06-09
CVE-2026-44705tmp: Path Traversal via unsanitized prefix/postfix enables directory escapeUNKNOWN28%ileMicrosoft2026-06-09
CVE-2026-48681OSSA-2026-018: File overwrite on Ironic conductor via path traversal in ISO handlingUNKNOWN45%ileOpenStack2026-06-03
FG-IR-26-151Path traversal in CLI command allows deletion of root file systemUNKNOWNFortinet2026-07-14
FG-IR-26-115Arbitrary directory delete on vmimages delete featureUNKNOWNFortinet2026-04-14
FG-IR-26-114Multiple Path traversals in CLIUNKNOWNFortinet2026-04-14
FG-IR-26-122Path Traversal in CLIUNKNOWNFortinet2026-04-14