CVE z tagiem path-traversal — 200 wyników. ← Wszystkie tagi

CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
94.3% EPSS
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2017-12637 🔴 Łataj teraz KEV

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string…

7.5 CVSS
93.5% EPSS
sappath-traversal 2017-08-07
CVE-2015-3035 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0…

7.5 CVSS
93.1% EPSS
CVE-2016-0752 🔴 Łataj teraz KEV

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by le…

7.5 CVSS
91.0% EPSS
CVE-2024-27199 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

7.3 CVSS
92.0% EPSS
CVE-2015-4068 🔴 Łataj teraz KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) expor…

9.1 CVSS
80.4% EPSS
CVE-2016-3976 🔴 Łataj teraz KEV

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Secu…

7.5 CVSS
76.3% EPSS
CVE-2015-0666 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

7.5 CVSS
58.5% EPSS
ciscopath-traversal 2015-04-03
CVE-2014-0130 🔴 Łataj teraz KEV

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbin…

7.5 CVSS
57.0% EPSS
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2024-31848 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative…

9.8 CVSS
93.6% EPSS
path-traversal 2024-04-05
CVE-2024-31849 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative ac…

9.8 CVSS
92.2% EPSS
path-traversal 2024-04-05
CVE-2024-31850 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive informatio…

8.6 CVSS
89.9% EPSS
path-traversal 2024-04-05
CVE-2024-24809 🟠 Łataj w tym tygodniu

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can ac…

8.5 CVSS
90.1% EPSS
path-traversalxss 2024-04-10
CVE-2024-31851 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive informati…

8.6 CVSS
89.3% EPSS
path-traversal 2024-04-05
CVE-2022-31474 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

7.5 CVSS
92.3% EPSS
CVE-2020-36728 ⚪ Do wiadomości

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to …

6.5 CVSS
84.4% EPSS
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2009-4000 🔴 Łataj teraz

Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the …

10.0 CVSS
31.6% EPSS
hppath-traversal 2010-01-20
CVE-2024-50509 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product De…

8.6 CVSS
28.6% EPSS
path-traversal 2024-10-30
CVE-2010-0926 ⚪ Do wiadomości

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, an…

3.5 CVSS
52.4% EPSS
sambapath-traversal 2010-03-10
CVE-2022-1476 ⚪ Do wiadomości

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, a…

6.6 CVSS
35.3% EPSS
CVE-2023-6972 🟠 Łataj w tym tygodniu

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-ide…

9.8 CVSS
19.0% EPSS
CVE-2024-50508 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product De…

7.5 CVSS
26.3% EPSS
path-traversal 2024-10-30
CVE-2006-5028 ⚪ Do wiadomości

Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file …

5.0 CVSS
36.5% EPSS
CVE-2001-1586 🔴 Łataj teraz

Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vu…

10.0 CVSS
3.5% EPSS
CVE-2006-5487 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed ar…

10.0 CVSS
1.7% EPSS
CVE-2024-25386 🟡 Monitoruj

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

8.8 CVSS
7.2% EPSS
path-traversal 2024-03-01
CVE-2024-43955 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip droip allows Path Traversal.This issue affects Droip: from n/a through < 2.5.2.

10.0 CVSS
1.1% EPSS
CVE-2023-5241 🟠 Łataj w tym tygodniu

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to …

9.6 CVSS
2.5% EPSS
CVE-2010-0620 🔴 Łataj teraz

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitr…

9.3 CVSS
3.9% EPSS
CVE-2006-5846 ⚪ Do wiadomości

Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.

6.4 CVSS
18.3% EPSS
CVE-2026-32871 🔴 Łataj teraz

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is resp…

10.0 CVSS
0.1% EPSS
CVE-2026-33494 🟠 Łataj w tym tygodniu

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP …

10.0 CVSS
0.1% EPSS
orypath-traversal 2026-03-26
CVE-2026-27897 🔴 Łataj teraz

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload cont…

10.0 CVSS
0.1% EPSS
CVE-2026-22557 🟠 Łataj w tym tygodniu

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying …

10.0 CVSS
0.0% EPSS
path-traversal 2026-03-19
CVE-2026-33054 🔴 Łataj teraz

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI str…

10.0 CVSS
0.0% EPSS
CVE-2006-5125 ⚪ Do wiadomości

Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which tri…

5.0 CVSS
25.0% EPSS
CVE-2025-59793 🔴 Łataj teraz

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDire…

9.9 CVSS
0.5% EPSS
CVE-2025-30841 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a th…

9.9 CVSS
0.4% EPSS
path-traversal 2025-04-01
CVE-2009-4013 🟠 Łataj w tym tygodniu
os

Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vector…

9.8 CVSS
0.8% EPSS
CVE-2026-35031 🟠 Łataj w tym tygodniu

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, all…

9.9 CVSS
0.2% EPSS
CVE-2024-29672 🟡 Monitoruj

Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.

8.8 CVSS
5.6% EPSS
path-traversal 2024-04-05
CVE-2026-40342 🔴 Łataj teraz

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without fi…

9.9 CVSS
0.1% EPSS
CVE-2026-1830 🟠 Łataj w tym tygodniu

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code…

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-09
CVE-2026-22562 🟠 Łataj w tym tygodniu

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affec…

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-13
CVE-2025-69874 🔴 Łataj teraz

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containi…

9.8 CVSS
0.1% EPSS
CVE-2026-35471 🔴 Łataj teraz

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.

9.8 CVSS
0.1% EPSS
CVE-2026-6057 🟠 Łataj w tym tygodniu

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

9.8 CVSS
0.1% EPSS
path-traversalrce 2026-04-10
CVE-2026-39813 🟠 Łataj w tym tygodniu
network

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

9.8 CVSS
0.1% EPSS
CVE-2026-4619 🟠 Łataj w tym tygodniu

Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

9.8 CVSS
0.1% EPSS
necpath-traversal 2026-03-27
CVE-2026-32771 🔴 Łataj teraz

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/ex…

9.8 CVSS
0.0% EPSS
CVE-2026-33195 🟠 Łataj w tym tygodniu

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem p…

9.8 CVSS
0.0% EPSS
CVE-2023-6699 🟠 Łataj w tym tygodniu

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated att…

9.1 CVSS
3.4% EPSS
CVE-2006-5733 🟡 Monitoruj

Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by …

7.5 CVSS
11.2% EPSS
CVE-2024-49286 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Events ssv-events allows PHP Local File Inclusion.This issue affects SSV Events: from n/a through <= 3.2…

9.6 CVSS
0.7% EPSS
CVE-2024-44014 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager allows PHP Local File Inclusion.This issue affects Vmax Project Manage…

9.6 CVSS
0.6% EPSS
lfipath-traversal 2024-10-05
CVE-2025-15036 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v…

9.6 CVSS
0.1% EPSS
path-traversal 2026-03-30
CVE-2026-28373 🟠 Łataj w tym tygodniu

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary con…

9.6 CVSS
0.0% EPSS
path-traversal 2026-04-03
CVE-2026-33211 🟠 Łataj w tym tygodniu

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vuln…

9.6 CVSS
0.0% EPSS
CVE-2026-2493 🟡 Monitoruj

IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not req…

7.5 CVSS
10.3% EPSS
path-traversal 2026-03-16
CVE-2023-5414 🟠 Łataj w tym tygodniu

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbi…

9.1 CVSS
2.1% EPSS
CVE-2006-5596 🟡 Monitoruj

Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

7.5 CVSS
9.8% EPSS
CVE-2024-39619 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <=…

9.0 CVSS
1.7% EPSS
CVE-2024-24042 🟡 Monitoruj

Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirect in RuntimeResourcePackImpl component.

8.8 CVSS
2.6% EPSS
path-traversal 2024-03-19
CVE-2022-4030 🟡 Monitoruj

The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attac…

8.1 CVSS
6.0% EPSS
CVE-2024-7387 🟠 Łataj w tym tygodniu

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using…

9.1 CVSS
0.8% EPSS
path-traversalrce 2024-09-17
CVE-2024-47637 🟡 Monitoruj

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

8.8 CVSS
2.2% EPSS
CVE-2026-35174 🟠 Łataj w tym tygodniu

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change t…

9.1 CVSS
0.5% EPSS
CVE-2024-28335 🟠 Łataj w tym tygodniu

Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses Ja…

9.1 CVSS
0.4% EPSS
path-traversal 2024-03-27
CVE-2026-35573 🔴 Łataj teraz

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve r…

9.1 CVSS
0.3% EPSS
CVE-2026-40258 🟠 Łataj w tym tygodniu

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. An authenticated us…

9.1 CVSS
0.1% EPSS
path-traversal 2026-04-17
CVE-2026-39847 🟠 Łataj w tym tygodniu

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attac…

9.1 CVSS
0.1% EPSS
CVE-2006-5510 ⚪ Do wiadomości

Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, as demonstrated by uploading a .gif fil…

6.4 CVSS
13.6% EPSS
CVE-2026-33183 🟠 Łataj w tym tygodniu

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file paths under the configured fixture directory without validation. A name con…

9.1 CVSS
0.0% EPSS
CVE-2024-52396 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3.

8.8 CVSS
1.3% EPSS
CVE-2009-4645 🟡 Monitoruj

Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

7.8 CVSS
6.3% EPSS
CVE-2026-3838 🟡 Monitoruj

Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit th…

8.8 CVSS
1.2% EPSS
CVE-2026-4092 🟡 Monitoruj
cloud

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequ…

8.8 CVSS
1.1% EPSS
CVE-2025-66074 🟠 Łataj w tym tygodniu

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8.

9.0 CVSS
0.1% EPSS
path-traversal 2025-12-18
CVE-2026-39305 🔴 Łataj teraz

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the…

9.0 CVSS
0.1% EPSS
CVE-2006-5263 🟡 Monitoruj

Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated…

7.5 CVSS
7.0% EPSS
CVE-2026-39981 🟡 Monitoruj

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An a…

8.8 CVSS
0.5% EPSS
path-traversal 2026-04-09
CVE-2006-5866 ⚪ Do wiadomości

Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.

6.4 CVSS
12.4% EPSS
CVE-2026-32060 🟡 Monitoruj

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without fi…

8.8 CVSS
0.4% EPSS
CVE-2009-2693 ⚪ Do wiadomości
apps

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrate…

5.8 CVSS
15.3% EPSS
CVE-2025-67030 🟡 Monitoruj

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

8.8 CVSS
0.3% EPSS
CVE-2006-5554 🟡 Monitoruj

Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter…

7.5 CVSS
6.7% EPSS
CVE-2024-39624 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.

8.5 CVSS
1.7% EPSS
CVE-2026-27040 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31.

8.8 CVSS
0.1% EPSS
path-traversal 2026-03-25
CVE-2026-33686 🟡 Monitoruj

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, all…

8.8 CVSS
0.1% EPSS
CVE-2026-5027 🟡 Monitoruj

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../…

8.8 CVSS
0.1% EPSS
path-traversal 2026-03-27
CVE-2022-45829 🟡 Monitoruj

Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.

8.7 CVSS
0.5% EPSS
CVE-2026-3666 🟡 Monitoruj

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes…

8.8 CVSS
0.0% EPSS
path-traversal 2026-04-04
CVE-2010-0759 🟡 Monitoruj

Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and …

7.5 CVSS
6.4% EPSS
CVE-2006-5894 ⚪ Do wiadomości

Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as…

6.8 CVSS
9.8% EPSS
CVE-2009-4679 🟡 Monitoruj

Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller …

7.5 CVSS
6.3% EPSS
CVE-2026-34728 🟠 Łataj w tym tygodniu

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied n…

8.7 CVSS
0.2% EPSS
CVE-2026-35214 🟠 Łataj w tym tygodniu

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path tr…

8.7 CVSS
0.1% EPSS
CVE-2024-49253 🟡 Monitoruj

Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.

8.6 CVSS
0.4% EPSS
path-traversal 2024-10-16
CVE-2025-4123 🟡 Monitoruj

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will exec…

7.6 CVSS
5.3% EPSS
CVE-2024-49315 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n…

8.6 CVSS
0.2% EPSS
path-traversal 2024-10-17
CVE-2024-33568 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BdThemes Element Pack Pro bdthemes-element-pack.This issue affects Element Pack Pro: from n/a through < 7.19.3.

8.5 CVSS
0.7% EPSS
CVE-2026-33513 🟠 Łataj w tym tygodniu

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist.…

8.6 CVSS
0.1% EPSS
CVE-2026-27305 🟡 Monitoruj

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker c…

8.6 CVSS
0.1% EPSS
adobepath-traversal 2026-04-14
CVE-2025-68912 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal.This issue affects HDForms: from n/a through <= 1.6.1.

8.6 CVSS
0.1% EPSS
path-traversal 2026-01-22
CVE-2026-31913 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16.

8.6 CVSS
0.1% EPSS
path-traversal 2026-03-25
CVE-2026-32522 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This issue affects WooCom…

8.6 CVSS
0.1% EPSS
path-traversal 2026-03-25
CVE-2025-60227 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.This issue affects WP Pipes: from n/a through <= 1.4.3.

8.6 CVSS
0.1% EPSS
CVE-2026-33166 🟠 Łataj w tym tygodniu

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing te…

8.6 CVSS
0.0% EPSS
CVE-2025-68901 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0.

8.6 CVSS
0.0% EPSS
path-traversal 2026-01-22
CVE-2025-69097 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through <= 1.9.9.5.4.

8.6 CVSS
0.0% EPSS
path-traversal 2026-01-22
CVE-2006-5735 🟡 Monitoruj

Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the language parameter, related to regis…

7.5 CVSS
5.1% EPSS
punbbpath-traversal 2006-11-06
CVE-2026-40318 🟡 Monitoruj

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without valid…

8.5 CVSS
0.1% EPSS
b3logpath-traversal 2026-04-16
CVE-2025-59711 🟡 Monitoruj

An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce…

8.3 CVSS
0.7% EPSS
kovaipath-traversal 2026-04-03
CVE-2010-0985 🟡 Monitoruj

Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to…

7.5 CVSS
4.5% EPSS
CVE-2026-35570 🟡 Monitoruj

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`.…

8.4 CVSS
0.0% EPSS
path-traversal 2026-04-21
CVE-2006-5786 🟡 Monitoruj

Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.

7.5 CVSS
4.3% EPSS
CVE-2026-32725 🟠 Łataj w tym tygodniu

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library n…

8.3 CVSS
0.2% EPSS
CVE-2026-34524 🟠 Łataj w tym tygodniu

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path trave…

8.3 CVSS
0.1% EPSS
CVE-2026-31939 🟡 Monitoruj

Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into…

8.3 CVSS
0.1% EPSS
CVE-2010-0972 🟡 Monitoruj

Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.…

7.5 CVSS
3.9% EPSS
CVE-2024-39621 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <=…

8.0 CVSS
1.2% EPSS
CVE-2006-5319 ⚪ Do wiadomości

Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter.

5.0 CVSS
16.1% EPSS
CVE-2026-22171 🟡 Monitoruj

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.…

8.2 CVSS
0.0% EPSS
CVE-2010-0696 ⚪ Do wiadomości

Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot)…

5.0 CVSS
16.0% EPSS
CVE-2026-33466 🟡 Monitoruj
apps

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction util…

8.1 CVSS
0.4% EPSS
CVE-2009-4672 🟡 Monitoruj

Directory traversal vulnerability in main.php in the WP-Lytebox plugin 1.3 for WordPress allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pg parameter.

7.5 CVSS
3.4% EPSS
CVE-2026-5966 🟡 Monitoruj

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.

8.1 CVSS
0.3% EPSS
path-traversal 2026-04-20
CVE-2026-34783 🟠 Łataj w tym tygodniu

Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write arbitrary files to …

8.1 CVSS
0.2% EPSS
CVE-2026-33949 🟡 Monitoruj

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This i…

8.1 CVSS
0.1% EPSS
sswpath-traversal 2026-04-01
CVE-2025-40898 🟡 Monitoruj

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-craf…

8.1 CVSS
0.1% EPSS
CVE-2026-32808 🟠 Łataj w tym tygodniu

pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypted 7z archives (encrypted files with non-…

8.1 CVSS
0.1% EPSS
CVE-2026-22661 🟡 Monitoruj

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized …

8.1 CVSS
0.1% EPSS
fkapath-traversal 2026-04-03
CVE-2026-34522 🟠 Łataj w tym tygodniu

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path trave…

8.1 CVSS
0.1% EPSS
CVE-2026-4351 🟡 Monitoruj

The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action…

8.1 CVSS
0.1% EPSS
dospath-traversal 2026-04-10
CVE-2026-32727 🟠 Łataj w tym tygodniu

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to e…

8.1 CVSS
0.1% EPSS
CVE-2026-33236 🟠 Łataj w tym tygodniu

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does…

8.1 CVSS
0.0% EPSS
CVE-2025-14037 🟡 Monitoruj

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createMa…

8.1 CVSS
0.0% EPSS
path-traversal 2026-03-21
CVE-2026-33293 🟠 Łataj w tym tygodniu

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with …

8.1 CVSS
0.0% EPSS
CVE-2026-33989 🟠 Łataj w tym tygodniu

Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_s…

8.1 CVSS
0.0% EPSS
CVE-2026-4350 🟡 Monitoruj

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['de…

8.1 CVSS
0.0% EPSS
path-traversal 2026-04-03
CVE-2025-39467 🟡 Monitoruj

Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.7.1.

8.1 CVSS
0.0% EPSS
CVE-2025-48090 🟡 Monitoruj

Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5.

8.1 CVSS
0.0% EPSS
lfipath-traversal 2025-11-06
CVE-2025-41368 🟡 Monitoruj

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the app…

8.1 CVSS
0.0% EPSS
CVE-2009-4683 🟡 Monitoruj

Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of …

7.5 CVSS
2.6% EPSS
CVE-2019-25579 🟡 Monitoruj

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadma…

7.5 CVSS
2.5% EPSS
CVE-2006-5320 ⚪ Do wiadomości

Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter.

5.0 CVSS
14.9% EPSS
CVE-2009-4723 🟡 Monitoruj

Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

7.5 CVSS
2.4% EPSS
CVE-2010-1043 🟡 Monitoruj

Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.

7.5 CVSS
2.3% EPSS
CVE-2010-1003 ⚪ Do wiadomości

Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.

6.8 CVSS
5.6% EPSS
CVE-2010-0680 🟡 Monitoruj

Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

7.5 CVSS
1.7% EPSS
CVE-2024-51582 🟡 Monitoruj

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

7.5 CVSS
1.7% EPSS
CVE-2026-0651 🟡 Monitoruj
network

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded inpu…

7.8 CVSS
0.1% EPSS
CVE-2026-32711 🟡 Monitoruj

pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside t…

7.8 CVSS
0.0% EPSS
CVE-2026-28518 🟡 Monitoruj

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers ca…

7.8 CVSS
0.0% EPSS
CVE-2010-1058 ⚪ Do wiadomości

Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot d…

6.8 CVSS
5.0% EPSS
CVE-2024-32703 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.

7.7 CVSS
0.4% EPSS
CVE-2024-50453 🟡 Monitoruj

Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pack Elementor addons: from n/a through <= 2.0.9.

7.5 CVSS
1.4% EPSS
CVE-2024-31457 🟡 Monitoruj

gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding to version 2.6.1, ha…

7.7 CVSS
0.3% EPSS
path-traversal 2024-04-09
CVE-2024-32778 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a thr…

7.7 CVSS
0.3% EPSS
CVE-2024-47351 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path Traversal.This issue affects MaxSlider: from n/a through <= 1.2.3.

7.5 CVSS
1.3% EPSS
path-traversal 2024-10-16
CVE-2024-37497 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetThemeCore jet-theme-core.This issue affects JetThemeCore: from n/a through < 2.2.1.

7.7 CVSS
0.2% EPSS
path-traversal 2024-07-09
CVE-2024-49245 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a through <= 1.0.0.

7.5 CVSS
1.2% EPSS
path-traversal 2024-10-16
CVE-2010-1057 ⚪ Do wiadomości

Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..// (dot dot slas…

6.8 CVSS
4.6% EPSS
CVE-2024-44013 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a thro…

7.5 CVSS
1.1% EPSS
lfipath-traversal 2024-10-05
CVE-2025-64230 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-protection allows Path Traversal.This issue affects Filr: from n/a through <= 1.2.10.

7.7 CVSS
0.1% EPSS
path-traversal 2025-12-18
CVE-2025-67914 🟡 Monitoruj

Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: from n/a through <= 2.3.8.

7.7 CVSS
0.1% EPSS
path-traversal 2026-01-08
CVE-2026-24970 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.2.

7.7 CVSS
0.1% EPSS
path-traversal 2026-03-25
CVE-2025-60217 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt-luxa-addons allows Path Traversal.This issue affects PT Luxa Addons: from n/a through <= 1.2.2.

7.7 CVSS
0.1% EPSS
path-traversal 2025-10-22
CVE-2025-58959 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Taskbot taskbot allows Path Traversal.This issue affects Taskbot: from n/a through <= 6.4.

7.7 CVSS
0.1% EPSS
path-traversal 2025-10-22
CVE-2026-24969 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a through <= 1.0.1.

7.7 CVSS
0.1% EPSS
path-traversal 2026-03-25
CVE-2026-35668 🟡 Monitoruj

OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other agents' workspaces via unnormalized mediaUrl or fileUrl parameter keys…

7.7 CVSS
0.1% EPSS
path-traversal 2026-04-10
CVE-2025-59566 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a t…

7.7 CVSS
0.0% EPSS
path-traversal 2025-10-22
CVE-2024-47645 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpoptin allows PHP Local File Inclusion.This issue affects Top Bar – PopUps –…

7.5 CVSS
1.0% EPSS
lfipath-traversal 2024-10-16
CVE-2006-5113 🟡 Monitoruj

Directory traversal vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to include and execute local files via a .. (dot dot) in the lan parameter to includes.php. NOTE: the provenance o…

7.5 CVSS
0.9% EPSS
CVE-2006-6033 🟡 Monitoruj

Multiple directory traversal vulnerabilities in Simple PHP Blog (SPHPBlog), probably 0.4.8, allow remote attackers to read arbitrary files and possibly include arbitrary PHP code via a .. (dot dot) sequence in the blog_t…

7.5 CVSS
0.9% EPSS
CVE-2024-47324 🟡 Monitoruj

Path Traversal: '.../...//' vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.…

7.5 CVSS
0.9% EPSS
path-traversal 2024-10-05
CVE-2024-49285 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV MailChimp ssv-mailchimp allows PHP Local File Inclusion.This issue affects SSV MailChimp: from n/a throu…

7.5 CVSS
0.8% EPSS
lfipath-traversal 2024-10-17
CVE-2026-33476 🟡 Monitoruj

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can…

7.5 CVSS
0.7% EPSS
CVE-2024-44018 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue …

7.5 CVSS
0.7% EPSS
lfipath-traversal 2024-10-05
CVE-2025-66687 🟡 Monitoruj

Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files

7.5 CVSS
0.7% EPSS
path-traversal 2026-03-16
CVE-2024-44011 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue af…

7.5 CVSS
0.7% EPSS
lfipath-traversal 2024-10-05
CVE-2024-44012 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subscription allows PHP Local File Inclusion.This issue affects WP Newslett…

7.5 CVSS
0.7% EPSS
lfipath-traversal 2024-10-05
CVE-2024-44015 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP Local File Inclusion.This issue affects Users Control: from n/a through …

7.5 CVSS
0.7% EPSS
lfipath-traversal 2024-10-05
CVE-2006-5149 🟡 Monitoruj

Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab p…

7.5 CVSS
0.7% EPSS
CVE-2024-31978 🟡 Monitoruj

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The corresponding API endpoint is susceptible to path traversal and could …

7.6 CVSS
0.2% EPSS
path-traversal 2024-04-09
CVE-2024-49287 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Rechnungsverwaltung pdf-rechnungsverwaltung allows PHP Local File Inclusion.This issue affects PDF-Rec…

7.5 CVSS
0.7% EPSS
lfipath-traversal 2024-10-17
CVE-2024-44034 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through <= 1.0.2.

7.5 CVSS
0.7% EPSS
lfipath-traversal 2024-10-05
CVE-2024-44017 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1.

7.5 CVSS
0.6% EPSS
lfipath-traversal 2024-10-02
CVE-2024-44016 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1.

7.5 CVSS
0.6% EPSS
lfipath-traversal 2024-10-05
CVE-2006-5731 ⚪ Do wiadomości

Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstr…

6.4 CVSS
6.1% EPSS
CVE-2006-5617 🟡 Monitoruj

Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file …

7.5 CVSS
0.6% EPSS
CVE-2026-32055 🟡 Monitoruj

OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existe…

7.6 CVSS
0.1% EPSS
CVE-2025-25371 🟡 Monitoruj

NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.

7.5 CVSS
0.5% EPSS
CVE-2006-5604 🟡 Monitoruj

Directory traversal vulnerability in phpcards.header.php in phpCards 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CardLanguageFile parameter.

7.5 CVSS
0.5% EPSS
CVE-2019-6268 🟡 Monitoruj

RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.

7.5 CVSS
0.5% EPSS
path-traversal 2024-03-08
CVE-2010-1056 ⚪ Do wiadomości

Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parame…

6.8 CVSS
4.0% EPSS