CWE-22
CVEs classified under CWE-22, newest first.
1061 CVEsRSS
CVE-2026-54468Medium· 6.5Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.
CVE-2026-55852NoneFrappe is a full-stack web application framework
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 …
CVE-2026-42219NoneFrappe is a full-stack web application framework
Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hardening. This issue is fixed in versions 16.19.0 and 15.109.0.
CVE-2026-41482NoneFrappe is a full-stack web application framework
Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.
CVE-2026-58499High· 8.2EverOS is a memory runtime for agents
EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint because the per-message sender_id field was not validated as a path-safe identifier, unlike a…
CVE-2026-55469Medium· 6.5Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deleti…
CVE-2026-54066High· 7.5PoCSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
GHSA-qv4m-m73m-8hj7High· 8.8NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
GHSA-wm45-qh3g-v83fHigh· 7.7mcp-atlassian: Arbitrary server-side file read via attachment upload
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-g5r6-gv6m-f5jvHigh· 7.7mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
CVE-2026-47826Critical· 9.1The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
CVE-2026-39245Medium· 6.2decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write
decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.…
GHSA-52vm-mxx8-f227High· 7.7Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
GHSA-c43v-4cr8-6mvpLowCraft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
CVE-2026-55874High· 7.7SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874)
A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user,…
CVE-2026-59820Medium· 6.5LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authen…
CVE-2026-27823CriticalEGroupware has a Remote Code Execution Vulnerability
EGroupware has a Remote Code Execution Vulnerability
CVE-2026-35363Medium· 5.6rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
CVE-2026-53486Critical· 9.1Decompress: Archive extraction can create files and links outside of the target directory
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2026-54760CriticalLangroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
CVE-2026-35338High· 7.3chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
CVE-2026-14628Medium· 5.3PoCA vulnerability was detected in NousResearch hermes-agent up to 2026.5.16
A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path tr…
CVE-2026-28705NoneGitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
CVE-2026-41124Low· 2.3Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limi…
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limi…
CVE-2026-47896NoneImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta0…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta0…
CVE-2026-47897NoneImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00…
CVE-2026-9725Critical· 9.1The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() func…
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() func…
CVE-2026-14352High· 7.5The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter
The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of …
CVE-2026-9559Critical· 9.9Mautic vulnerable to Path Traversal via Campaign Import
Mautic vulnerable to Path Traversal via Campaign Import
GHSA-322x-v876-g883High@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write