CWE-23
CVEs classified under CWE-23, newest first.
61 CVEsRSS
CVE-2026-70337High· 8.8Microsoft PowerShell Remote Code Execution Vulnerability
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
CVE-2026-62837Medium· 6.5Microsoft SharePoint Server Information Disclosure Vulnerability
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-65810High· 7.8.NET Framework Elevation of Privilege Vulnerability
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-10595High· 7.5A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, wh…
CVE-2026-18907High· 7.5PoCPath Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
CVE-2026-54910High· 7.7FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
CVE-2026-55100Highhashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …
CVE-2026-6540High· 7.5Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes …
CVE-2026-62843Medium· 6.8File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVE-2026-50663High· 8.8Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
CVE-2026-50426Medium· 6.8Windows DNS Server Remote Code Execution Vulnerability
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
CVE-2026-56196High· 8.8Windows Admin Center (WAC) Remote Code Execution Vulnerability
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-50454High· 7.8Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-40400High· 8.0Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVE-2026-55474Medium· 6.5Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to…
CVE-2026-54066High· 7.5PoCSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
CVE-2026-14476High· 8.0A path traversal flaw was found in SSSD's AD GPO provider
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write file…
CVE-2026-57988High· 7.1Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58522Medium· 6.8Microsoft Edge for Android Information Disclosure Vulnerability
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-50181High· 7.1PoCLangroid: Path traversal in the file tools allows read/write outside configured current directory
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVE-2026-8023High· 7.5PoCZephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both …
CVE-2026-50016High· 8.8pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVE-2026-52813Critical· 10.0PoCGogs has Path Traversal in organization name that results in RCE through Git hooks
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-48126High· 8.2Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
CVE-2026-10720MediumCanonical MicroCeph: path traversal issue in the remote-import AP
Canonical MicroCeph: path traversal issue in the remote-import AP
GHSA-jvcm-f35g-w78pMedium· 6.5Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
GHSA-48x2-6pr9-2jjfMedium· 6.1Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
CVE-2026-23734NoneXWiki Platform is a generic wiki platform
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwi…
CVE-2026-31927Medium· 4.9Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
CVE-2026-21620NoneRelative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. Thi…