VulnSea

CWE-23

CVEs classified under CWE-23, newest first.

61 CVEsRSS

CVE-2026-70337High· 8.8
1mo ago

Microsoft PowerShell Remote Code Execution Vulnerability

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · PowerShell 7.4EPSS 0.80%via CVEORG
CVE-2026-62837Medium· 6.5
1mo ago

Microsoft SharePoint Server Information Disclosure Vulnerability

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.86%via CVEORG
CVE-2026-65810High· 7.8
1mo ago

.NET Framework Elevation of Privilege Vulnerability

Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft .NET Framework 3.5EPSS 0.27%via CVEORG
CVE-2026-10595High· 7.5
1mo ago

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, wh…

TwilightEPSS 0.49%via NVD
CVE-2026-18907High· 7.5PoC
1mo ago

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

MidnightEPSS 0.66%via NVD
CVE-2026-54910High· 7.7
1mo ago

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

Twilightgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.46%via GHSA
CVE-2026-55100High
1mo ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …

Twilighthashi-vault-js · hashi-vault-jsEPSS 0.38%via NVD
CVE-2026-6540High· 7.5
1mo ago

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes …

Twilighttigera · calicoEPSS 0.37%via NVD
CVE-2026-62843Medium· 6.8
2mo ago

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.39%via GHSA
CVE-2026-50663High· 8.8
2mo ago

Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Age of Empires II: Definitive Edition GameEPSS 0.94%via CVEORG
CVE-2026-50426Medium· 6.8
2mo ago

Windows DNS Server Remote Code Execution Vulnerability

Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.56%via CVEORG
CVE-2026-56196High· 8.8
2mo ago

Windows Admin Center (WAC) Remote Code Execution Vulnerability

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Windows Admin CenterEPSS 0.95%via CVEORG
CVE-2026-50454High· 7.8
2mo ago

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.37%via NVD
CVE-2026-40400High· 8.0
2mo ago

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.87%via NVD
CVE-2026-55474Medium· 6.5
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to…

Sunlitsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-14476High· 8.0
2mo ago

A path traversal flaw was found in SSSD's AD GPO provider

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write file…

TwilightEPSS 0.67%via NVD
CVE-2026-57988High· 7.1
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.76%via CVEORG
CVE-2026-58522Medium· 6.8
2mo ago

Microsoft Edge for Android Information Disclosure Vulnerability

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.43%via CVEORG
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Midnightlangroid · langroidEPSS 0.18%via GHSA
CVE-2026-8023High· 7.5PoC
2mo ago

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both …

Midnightzephyrproject · zephyrEPSS 0.87%via NVD
CVE-2026-50016High· 8.8
2mo ago

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

Twilightpnpm · pnpmEPSS 0.53%via GHSA
CVE-2026-52813Critical· 10.0PoC
3mo ago

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Abyssalgogs · gogs.io/gogsEPSS 1.1%via GHSA
CVE-2026-48126High· 8.2
3mo ago

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

Twilightxyproto · github.com/xyproto/algernonEPSS 0.34%via GHSA
CVE-2026-10720Medium
3mo ago

Canonical MicroCeph: path traversal issue in the remote-import AP

Canonical MicroCeph: path traversal issue in the remote-import AP

Sunlitcanonical · github.com/canonical/microceph/microcephEPSS 0.30%via GHSA
GHSA-jvcm-f35g-w78pMedium· 6.5
3mo ago

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

Sunlitnetwork-ai · network-aivia GHSA
GHSA-48x2-6pr9-2jjfMedium· 6.1
3mo ago

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

Sunlitnetwork-ai · network-aivia GHSA
CVE-2026-23734None
4mo ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwi…

SunlitEPSS 20%via NVD
CVE-2026-31927Medium· 4.9
5mo ago

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

Sunlitanviz · cx7_firmwareEPSS 0.35%via NVD
CVE-2026-21620None
7mo ago

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. Thi…

SunlitEPSS 0.48%via NVD
CWE-23 vulnerabilities (CVEs) — page 2 · VulnSea