100 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-67429 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi | CRITICAL | 10.0 | 40%ile | NVD | 2026-07-29 |
| CVE-2026-59310 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access | CRITICAL | 9.8 | 64%ile | NVD | 2026-07-30 |
| CVE-2026-15435 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to t | CRITICAL | 9.8 | 51%ile | NVD | 2026-07-30 |
| CVE-2026-52680 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary | CRITICAL | 9.8 | 43%ile | NVD | 2026-07-30 |
| CVE-2026-14973 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's s | CRITICAL | 9.3 | 37%ile | NVD | 2026-07-28 |
| CVE-2026-69110 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2026-65889 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allow | CRITICAL | 9.2 | 25%ile | NVD | 2026-07-29 |
| CVE-2026-65886 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut | CRITICAL | 9.2 | 29%ile | NVD | 2026-07-29 |
| CVE-2026-3141 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec | CRITICAL | 9.1 | 38%ile | NVD | 2026-08-01 |
| CVE-2026-58072 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead | CRITICAL | 9.0 | — | NVD | 2026-08-04 |
| CVE-2025-69194 | Wget2: arbitrary file write via metalink path traversal in gnu wget2 | HIGH | 8.8 | 50%ile | Microsoft | 2026-01-13 |
| CVE-2025-47273 | setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write | HIGH | 8.8 | 71%ile | Microsoft | 2025-05-13 |
| CVE-2025-51480 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit | HIGH | 8.8 | 44%ile | Microsoft | 2025-07-08 |
| CVE-2026-55100 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenat | HIGH | 8.7 | 31%ile | NVD | 2026-07-31 |
| CVE-2026-53502 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path | HIGH | 8.7 | 28%ile | NVD | 2026-07-31 |
| CVE-2026-69089 | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image | HIGH | 8.7 | 30%ile | NVD | 2026-08-03 |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in | HIGH | 8.7 | 46%ile | NVD | 2026-08-03 |
| CVE-2026-67200 | Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary | HIGH | 8.7 | — | NVD | 2026-08-04 |
| CVE-2026-54650 | openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ | HIGH | 8.6 | 29%ile | NVD | 2026-07-28 |
| CVE-2026-11974 | The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in | HIGH | 8.6 | 39%ile | NVD | 2026-07-29 |
| CVE-2026-66415 | Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated a | HIGH | 8.4 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-58177 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is | HIGH | 8.3 | 43%ile | NVD | 2026-07-29 |
| CVE-2026-69086 | SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, | HIGH | 8.3 | 28%ile | NVD | 2026-08-03 |
| CVE-2026-62391 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend | HIGH | 8.1 | 33%ile | NVD | 2026-07-31 |
| CVE-2026-15450 | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path trav | HIGH | 8.1 | 30%ile | NVD | 2026-08-01 |
| CVE-2026-11816 | Path Traversal in keras-team/keras | HIGH | 8.1 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-6540 | Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR | HIGH | 7.9 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-48374 | Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th | HIGH | 7.8 | 9%ile | NVD | 2026-07-28 |
| CVE-2026-67309 | Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider | HIGH | 7.8 | 40%ile | NVD | 2026-08-01 |
| CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | HIGH | 7.7 | 23%ile | GitHub | 2026-07-31 |
| CVE-2026-15280 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segm | HIGH | 7.5 | 26%ile | NVD | 2026-07-28 |
| CVE-2026-55389 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch | HIGH | 7.5 | 29%ile | NVD | 2026-07-28 |
| CVE-2026-55390 | datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars | HIGH | 7.5 | 29%ile | NVD | 2026-07-28 |
| CVE-2026-5487 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo | HIGH | 7.5 | 72%ile | NVD | 2026-07-29 |
| CVE-2026-5491 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo | HIGH | 7.5 | 72%ile | NVD | 2026-07-29 |
| CVE-2026-14519 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r | HIGH | 7.5 | 46%ile | NVD | 2026-07-30 |
| CVE-2026-62663 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt | HIGH | 7.5 | 26%ile | NVD | 2026-07-30 |
| CVE-2026-12942 | IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c | HIGH | 7.5 | 34%ile | NVD | 2026-07-30 |
| CVE-2026-56671 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ | HIGH | 7.5 | 48%ile | NVD | 2026-07-31 |
| CVE-2026-56673 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path | HIGH | 7.5 | 35%ile | NVD | 2026-07-31 |
| CVE-2026-63222 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us | HIGH | 7.5 | 37%ile | NVD | 2026-07-31 |
| CVE-2026-62999 | Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-direc | HIGH | 7.5 | 22%ile | NVD | 2026-07-31 |
| CVE-2026-15006 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln | HIGH | 7.5 | 54%ile | NVD | 2026-08-01 |
| CVE-2026-13339 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1 | HIGH | 7.5 | 47%ile | NVD | 2026-08-02 |
| CVE-2026-18352 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, | HIGH | 7.5 | 49%ile | NVD | 2026-08-02 |
| CVE-2026-61372 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi | HIGH | 7.5 | 31%ile | NVD | 2026-08-03 |
| CVE-2026-56845 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur | HIGH | 7.5 | 29%ile | NVD | 2026-08-04 |
| CVE-2026-12072 | Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.p | HIGH | 7.5 | — | GitHub | 2026-07-31 |
| CVE-2026-12074 | Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, | HIGH | 7.5 | — | GitHub | 2026-07-31 |
| CVE-2026-14818 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi | HIGH | 7.2 | 29%ile | NVD | 2026-08-04 |
| CVE-2026-18192 | VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e | HIGH | 7.1 | 31%ile | NVD | 2026-07-29 |
| CVE-2026-67247 | A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlle | HIGH | 7.1 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-9856 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi | HIGH | 7.1 | 22%ile | NVD | 2026-08-02 |
| CVE-2026-54545 | @wakaru/cli arbitrary file write during bundle unpack | HIGH | 7.1 | 5%ile | GitHub | 2026-07-28 |
| CVE-2026-40024 | Sleuth Kit tsk_recover Path Traversal | HIGH | 7.1 | 6%ile | Microsoft | 2026-04-14 |
| CVE-2026-67245 | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled | HIGH | 7.0 | 11%ile | NVD | 2026-07-30 |
| CVE-2026-54659 | Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18 | MEDIUM | 6.9 | 30%ile | NVD | 2026-07-28 |
| CVE-2026-44943 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem | MEDIUM | 6.9 | 26%ile | NVD | 2026-07-29 |
| CVE-2026-67246 | A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-contro | MEDIUM | 6.9 | 24%ile | NVD | 2026-07-30 |
| CVE-2026-66063 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown. | MEDIUM | 6.5 | 14%ile | NVD | 2026-07-28 |
| CVE-2026-13723 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar | MEDIUM | 6.5 | 25%ile | NVD | 2026-07-29 |
| CVE-2026-5492 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo | MEDIUM | 6.5 | 73%ile | NVD | 2026-07-29 |
| CVE-2026-44615 | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi | MEDIUM | 6.5 | 40%ile | NVD | 2026-07-31 |
| CVE-2026-9335 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp | MEDIUM | 6.5 | 47%ile | NVD | 2026-08-02 |
| CVE-2026-14194 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor | MEDIUM | 6.5 | 36%ile | NVD | 2026-08-04 |
| CVE-2026-34978 | OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of | MEDIUM | 6.5 | 33%ile | Microsoft | 2026-04-14 |
| CVE-2026-69153 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract | MEDIUM | 6.3 | 28%ile | NVD | 2026-08-03 |
| CVE-2026-54785 | gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti | MEDIUM | 6.2 | 5%ile | NVD | 2026-07-31 |
| CVE-2026-50558 | Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d | MEDIUM | 5.9 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-66755 | Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0. | MEDIUM | 5.9 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-18646 | A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system | MEDIUM | 5.5 | 42%ile | NVD | 2026-08-03 |
| CVE-2026-64400 | ksmbd: prevent path traversal bypass by restricting caseless retry | MEDIUM | 5.5 | 28%ile | Microsoft | 2026-07-14 |
| CVE-2026-5489 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo | MEDIUM | 5.3 | 67%ile | NVD | 2026-07-29 |
| CVE-2026-16531 | An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a | MEDIUM | 5.3 | 28%ile | NVD | 2026-07-30 |
| CVE-2026-67295 | FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to | MEDIUM | 5.3 | 16%ile | NVD | 2026-08-01 |
| CVE-2026-5114 | The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and | MEDIUM | 4.9 | 27%ile | NVD | 2026-07-28 |
| CVE-2026-15601 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi | MEDIUM | 4.9 | 52%ile | NVD | 2026-08-01 |
| CVE-2026-17614 | A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getCo | MEDIUM | 4.4 | 55%ile | NVD | 2026-08-04 |
| CVE-2026-55495 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W | MEDIUM | 4.3 | 30%ile | NVD | 2026-07-31 |
| CVE-2026-35177 | Path traversal issue with zip.vim in Vim | MEDIUM | 4.1 | 3%ile | Microsoft | 2026-04-14 |
| CVE-2025-53906 | Vim has path traversal issue with zip.vim and special crafted zip archives | MEDIUM | 4.1 | 51%ile | Microsoft | 2025-07-08 |
| CVE-2026-55825 | Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can | LOW | 3.1 | 11%ile | NVD | 2026-07-31 |
| CVE-2026-18644 | A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file / | LOW | 2.1 | 30%ile | NVD | 2026-08-03 |
| CVE-2026-18645 | A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys | LOW | 2.1 | 35%ile | NVD | 2026-08-03 |
| CVE-2026-18648 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat | LOW | 1.9 | 7%ile | NVD | 2026-08-03 |
| GHSA-pmwx-rm49-xv39 | ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal | LOW | — | — | GitHub | 2026-07-29 |
| CVE-2026-67970 | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive co | UNKNOWN | — | 4%ile | NVD | 2026-08-03 |
| CVE-2026-34591 | Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write | UNKNOWN | — | 38%ile | Microsoft | 2026-04-14 |
| CVE-2026-32147 | SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT | UNKNOWN | — | 28%ile | Microsoft | 2026-04-14 |
| CVE-2026-41205 | Mako: Path traversal via double-slash URI prefix in TemplateLookup | UNKNOWN | — | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-41140 | Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 | UNKNOWN | — | 22%ile | Microsoft | 2026-04-14 |
| CVE-2026-44307 | Mako: Path traversal via backslash URI on Windows in TemplateLookup | UNKNOWN | — | 46%ile | Microsoft | 2026-05-12 |
| CVE-2025-59825 | astral-tokio-tar has a path traversal in tar extraction | UNKNOWN | — | 10%ile | Microsoft | 2025-09-09 |
| CVE-2026-7774 | tarfile.data_filter path traversal bypass allows writing outside the extraction directory | UNKNOWN | — | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-44705 | tmp: Path Traversal via unsanitized prefix/postfix enables directory escape | UNKNOWN | — | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-48681 | OSSA-2026-018: File overwrite on Ironic conductor via path traversal in ISO handling | UNKNOWN | — | 45%ile | OpenStack | 2026-06-03 |
| FG-IR-26-151 | Path traversal in CLI command allows deletion of root file system | UNKNOWN | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-115 | Arbitrary directory delete on vmimages delete feature | UNKNOWN | — | — | Fortinet | 2026-04-14 |
| FG-IR-26-114 | Multiple Path traversals in CLI | UNKNOWN | — | — | Fortinet | 2026-04-14 |
| FG-IR-26-122 | Path Traversal in CLI | UNKNOWN | — | — | Fortinet | 2026-04-14 |