← Back to feed Search feed

CWE-22 Path Traversal vulnerabilities

158 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-85706GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1CRITICAL10.096%ileNVD2026-09-12
CVE-2026-70200Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorizeCRITICAL10.047%ileNVD2026-09-17
CVE-2025-62878Local Path Provisioner vulnerable to Path Traversal via parameters.pathPatternCRITICAL9.946%ileMicrosoft2026-02-10
CVE-2026-76440As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and CiscCRITICAL9.839%ileNVD2026-09-14
CVE-2026-61560`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`CRITICAL9.852%ileNVD2026-09-15
CVE-2026-54617GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote CRITICAL9.851%ileNVD2026-09-17
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote aCRITICAL9.861%ileNVD2026-09-17
CVE-2026-54053Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implCRITICAL9.652%ileNVD2026-09-17
CVE-2026-89040Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request iCRITICAL9.359%ileNVD2026-09-15
CVE-2026-70009Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacCRITICAL9.340%ileNVD2026-09-17
CVE-2026-78299In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extrCRITICAL9.128%ileNVD2026-09-14
CVE-2026-57145PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-contCRITICAL9.130%ileNVD2026-09-14
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL froCRITICAL9.154%ileNVD2026-09-14
CVE-2026-54670WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contCRITICAL9.145%ileNVD2026-09-17
CVE-2026-82428Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from tHIGH8.851%ileNVD2026-09-14
CVE-2026-92137Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot FrameworHIGH8.854%ileNVD2026-09-16
CVE-2026-85731oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked wHIGH8.850%ileNVD2026-09-16
CVE-2026-89084HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, HIGH8.846%ileNVD2026-09-16
CVE-2026-76409As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering tHIGH8.842%ileNVD2026-09-16
CVE-2026-15815Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugHIGH8.857%ileNVD2026-09-17
CVE-2026-54612Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 untilHIGH8.841%ileNVD2026-09-17
CVE-2025-69194Wget2: arbitrary file write via metalink path traversal in gnu wget2HIGH8.855%ileMicrosoft2026-01-13
CVE-2026-90774rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowiHIGH8.732%ileNVD2026-09-13
CVE-2026-91200DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. AttackHIGH8.736%ileNVD2026-09-14
CVE-2026-91771Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download functionHIGH8.753%ileNVD2026-09-15
CVE-2026-87791A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress DesHIGH8.734%ileNVD2026-09-15
CVE-2026-91934Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databHIGH8.751%ileNVD2026-09-15
CVE-2026-91940crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untHIGH8.736%ileNVD2026-09-15
CVE-2026-91989atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remoteHIGH8.768%ileNVD2026-09-15
CVE-2026-81568Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-HIGH8.726%ileNVD2026-09-15
CVE-2026-92355In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a patHIGH8.751%ileNVD2026-09-16
CVE-2026-92748BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authentHIGH8.750%ileNVD2026-09-16
CVE-2026-92791Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attHIGH8.742%ileNVD2026-09-16
CVE-2026-92970HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticHIGH8.743%ileNVD2026-09-17
CVE-2026-86864pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pHIGH8.732%ileNVD2026-09-17
CVE-2026-54343Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version HIGH8.741%ileNVD2026-09-17
CVE-2026-93468The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit RHIGH8.739%ileNVD2026-09-18
CVE-2017-20284Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenHIGH8.7NVD2026-09-18
CVE-2026-82765Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is HIGH8.625%ileNVD2026-09-14
CVE-2026-82768Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may beHIGH8.629%ileNVD2026-09-14
CVE-2026-90932LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CHIGH8.639%ileNVD2026-09-14
CVE-2026-92816ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arHIGH8.55%ileNVD2026-09-16
CVE-2026-55062uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/unigetHIGH8.43%ileNVD2026-09-17
CVE-2026-54583mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dHIGH8.343%ileNVD2026-09-17
CVE-2026-54178backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH8.130%ileNVD2026-09-14
CVE-2026-16335IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, orHIGH8.136%ileNVD2026-09-14
CVE-2026-83357Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppoHIGH8.132%ileNVD2026-09-15
CVE-2026-54520AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior HIGH8.134%ileNVD2026-09-17
CVE-2026-62278LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenHIGH8.1NVD2026-09-18
CVE-2026-70460rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir SymlinkHIGH8.138%ileMicrosoft2026-08-11
CVE-2026-11816Path Traversal in keras-team/kerasHIGH8.146%ileMicrosoft2026-06-09
CVE-2026-82427Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the superviHIGH7.87%ileNVD2026-09-14
CVE-2026-43691A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS SequoiaHIGH7.88%ileNVD2026-09-14
CVE-2026-64790A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS SequoiaHIGH7.88%ileNVD2026-09-14
CVE-2026-84568A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS SHIGH7.86%ileNVD2026-09-14
CVE-2026-59974Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languageHIGH7.840%ileNVD2026-09-16
CVE-2026-79655Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file wrHIGH7.84%ileMicrosoft2026-08-11
CVE-2026-73496MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, thHIGH7.726%ileNVD2026-09-14
CVE-2026-92812decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix HIGH7.622%ileNVD2026-09-16
CVE-2026-82896IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due HIGH7.6NVD2026-09-18
CVE-2026-57129PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts fHIGH7.538%ileNVD2026-09-14
CVE-2026-57119PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversingHIGH7.530%ileNVD2026-09-14
CVE-2026-15955IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file writHIGH7.534%ileNVD2026-09-14
CVE-2026-54629Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtuHIGH7.560%ileNVD2026-09-14
CVE-2026-84598A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOSHIGH7.532%ileNVD2026-09-14
CVE-2026-51134The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameteHIGH7.579%ileNVD2026-09-15
CVE-2026-27557An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file HIGH7.552%ileNVD2026-09-16
CVE-2026-81481Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a ResHIGH7.544%ileNVD2026-09-17
CVE-2026-14323The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal inHIGH7.559%ileNVD2026-09-18
CVE-2025-14753IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could sendHIGH7.5NVD2026-09-18
CVE-2026-85396rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory PrefixHIGH7.532%ileMicrosoft2026-09-08
CVE-2026-82251gitoxide before 0.52.1 Path Traversal via Submodule NameHIGH7.533%ileMicrosoft2026-08-11
CVE-2026-82253gitoxide before 0.82.0 Path Traversal via Submodule Name Validation BypassHIGH7.542%ileMicrosoft2026-08-11
CVE-2026-78254Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file writeHIGH7.444%ileMicrosoft2026-09-08
CVE-2026-56839PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass HIGH7.323%ileNVD2026-09-14
CVE-2026-47253Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar functiHIGH7.331%ileNVD2026-09-14
CVE-2026-53554SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datHIGH7.330%ileNVD2026-09-17
CVE-2026-91751Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowingHIGH7.228%ileNVD2026-09-15
CVE-2026-92604Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows dHIGH7.243%ileNVD2026-09-16
CVE-2026-87976Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using gHIGH7.232%ileNVD2026-09-16
CVE-2026-92919admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to HIGH7.232%ileNVD2026-09-17
CVE-2026-84086IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper HIGH7.2NVD2026-09-18
CVE-2026-82035PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_oHIGH7.125%ileNVD2026-09-14
CVE-2026-54077ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/querHIGH7.131%ileNVD2026-09-15
CVE-2026-93014RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing HIGH7.133%ileNVD2026-09-17
CVE-2026-63445Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpointHIGH7.1NVD2026-09-18
CVE-2026-53784rsync < 3.5.0 Path Traversal via Symlink Module RootHIGH7.115%ileMicrosoft2026-08-11
CVE-2026-53785rsync < 3.5.0 Path Traversal Write Escape via --relative ModeHIGH7.19%ileMicrosoft2026-08-11
CVE-2026-82455RubyGems before 4.0.13 Path Traversal via Symlink ResolutionHIGH7.1Microsoft2026-08-11
CVE-2026-81564Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP PHIGH7.024%ileNVD2026-09-14
CVE-2026-90494A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plMEDIUM6.945%ileNVD2026-09-13
CVE-2026-81565Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.MEDIUM6.924%ileNVD2026-09-14
CVE-2026-54150next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-videMEDIUM6.931%ileNVD2026-09-14
CVE-2026-89021MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractioMEDIUM6.916%ileNVD2026-09-14
CVE-2026-57442MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, MEDIUM6.96%ileNVD2026-09-15
CVE-2026-89038Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows coMEDIUM6.94%ileNVD2026-09-17
CVE-2026-93751uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlonMEDIUM6.9NVD2026-09-18
CVE-2026-76555The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it aMEDIUM6.839%ileNVD2026-09-16
CVE-2026-82426Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a servMEDIUM6.542%ileNVD2026-09-14
CVE-2026-43791A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.539%ileNVD2026-09-14
CVE-2026-81453Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a ResMEDIUM6.538%ileNVD2026-09-17
CVE-2026-40535An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in SynoloMEDIUM6.537%ileNVD2026-09-18
CVE-2026-59149@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only MEDIUM6.541%ileGitHub2026-09-11
CVE-2026-21822HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handlMEDIUM6.312%ileNVD2026-09-18
CVE-2026-55846Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP serMEDIUM6.24%ileNVD2026-09-14
CVE-2026-54561MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_iMEDIUM6.223%ileNVD2026-09-15
CVE-2026-55832Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2MEDIUM6.115%ileNVD2026-09-14
CVE-2026-59944Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious orMEDIUM6.139%ileNVD2026-09-16
CVE-2026-55828qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses stricMEDIUM6.031%ileNVD2026-09-15
CVE-2026-54585mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c didMEDIUM6.043%ileNVD2026-09-17
CVE-2026-69201Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode MEDIUM5.949%ileNVD2026-09-15
CVE-2026-58015Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveMEDIUM5.950%ileMicrosoft2026-06-09
CVE-2026-90691A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impMEDIUM5.537%ileNVD2026-09-14
CVE-2026-64756A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden MEDIUM5.58%ileNVD2026-09-14
CVE-2026-65382A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in mMEDIUM5.57%ileNVD2026-09-14
CVE-2026-65411A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 anMEDIUM5.54%ileNVD2026-09-14
CVE-2026-84534A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 anMEDIUM5.55%ileNVD2026-09-14
CVE-2026-84541An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macMEDIUM5.55%ileNVD2026-09-14
CVE-2026-84624A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27MEDIUM5.54%ileNVD2026-09-14
CVE-2026-86886A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOMEDIUM5.53%ileNVD2026-09-14
CVE-2026-86902A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in mMEDIUM5.53%ileNVD2026-09-14
CVE-2026-86910A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS SequMEDIUM5.55%ileNVD2026-09-14
CVE-2026-64400ksmbd: prevent path traversal bypass by restricting caseless retryMEDIUM5.529%ileMicrosoft2026-07-14
CVE-2026-54613Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5MEDIUM5.415%ileNVD2026-09-17
CVE-2026-47256OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generatingMEDIUM5.336%ileNVD2026-09-14
CVE-2026-50024GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_taMEDIUM5.338%ileNVD2026-09-15
CVE-2026-76433A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticateMEDIUM5.359%ileNVD2026-09-16
CVE-2026-81829A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by MEDIUM5.333%ileNVD2026-09-17
CVE-2026-93013RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadatMEDIUM5.329%ileNVD2026-09-17
CVE-2026-76431A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC couMEDIUM4.965%ileNVD2026-09-16
CVE-2026-76432A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remotMEDIUM4.958%ileNVD2026-09-16
CVE-2026-76434A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISEMEDIUM4.919%ileNVD2026-09-16
CVE-2026-16777The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable toMEDIUM4.950%ileNVD2026-09-18
CVE-2026-47215SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.MEDIUM4.84%ileNVD2026-09-15
CVE-2026-48785Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefixMEDIUM4.82%ileNVD2026-09-15
CVE-2026-55374canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrMEDIUM4.814%ileNVD2026-09-15
CVE-2025-11563wcurl path traversal with percent-encoded slashesMEDIUM4.630%ileMicrosoft2026-02-10
CVE-2026-79705A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archMEDIUM4.516%ileNVD2026-09-15
CVE-2026-63225Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the splMEDIUM4.47%ileNVD2026-09-16
CVE-2026-18515IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with NavigaMEDIUM4.320%ileNVD2026-09-14
CVE-2026-40536An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in SynologyMEDIUM4.331%ileNVD2026-09-18
CVE-2026-85272Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and VerawoMEDIUM4.3NVD2026-09-18
CVE-2026-53584libgit2: Submodule path traversalMEDIUM4.326%ileMicrosoft2026-08-11
CVE-2026-92131Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to MEDIUM4.213%ileNVD2026-09-16
CVE-2026-86071Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/gitLOW3.723%ileNVD2026-09-16
CVE-2025-70820Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.LOW3.58%ileNVD2026-09-13
CVE-2026-45723Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreatLOW2.732%ileNVD2026-09-17
CVE-2026-92945vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefixLOW2.312%ileNVD2026-09-17
CVE-2025-59825astral-tokio-tar has a path traversal in tar extractionUNKNOWN12%ileMicrosoft2025-09-09
CVE-2026-64653GitHub CLI: Unescaped variable components in request URLs could allow path traversalUNKNOWN42%ileMicrosoft2026-08-11
CVE-2026-66484Path Traversal in GNU cpioUNKNOWN5%ileMicrosoft2026-08-11
CVE-2026-44307Mako: Path traversal via backslash URI on Windows in TemplateLookupUNKNOWN48%ileMicrosoft2026-05-12
CVE-2026-13346pip absolute path traversal during download from malicious package indexesUNKNOWN22%ileMicrosoft2026-07-14
CVE-2026-7774tarfile.data_filter path traversal bypass allows writing outside the extraction directoryUNKNOWN47%ileMicrosoft2026-06-09
CVE-2026-44705tmp: Path Traversal via unsanitized prefix/postfix enables directory escapeUNKNOWN37%ileMicrosoft2026-06-09
CVE-2026-1703Limited path traversal when installing wheel archivesUNKNOWN35%ileMicrosoft2026-02-10
CVE-2026-21620TFTP Path TraversalUNKNOWN39%ileMicrosoft2026-02-10
FG-IR-26-151Path traversal in CLI command allows deletion of root file systemUNKNOWNFortinet2026-07-14