CVE z tagiem path-traversal — 200 wyników. ← Wszystkie tagi

CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
94.3% EPSS
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2017-12637 🔴 Łataj teraz KEV

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string…

7.5 CVSS
93.5% EPSS
sappath-traversal 2017-08-07
CVE-2015-3035 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0…

7.5 CVSS
93.1% EPSS
CVE-2016-0752 🔴 Łataj teraz KEV

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by le…

7.5 CVSS
91.0% EPSS
CVE-2024-27199 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

7.3 CVSS
92.0% EPSS
CVE-2015-4068 🔴 Łataj teraz KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) expor…

9.1 CVSS
80.4% EPSS
CVE-2016-3976 🔴 Łataj teraz KEV

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Secu…

7.5 CVSS
76.3% EPSS
CVE-2015-0666 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

7.5 CVSS
58.5% EPSS
ciscopath-traversal 2015-04-03
CVE-2014-0130 🔴 Łataj teraz KEV

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbin…

7.5 CVSS
57.0% EPSS
CVE-2026-34909 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

10.0 CVSS
2.3% EPSS
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2026-34926 🔴 Łataj teraz KEV

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installa…

6.7 CVSS
0.2% EPSS
path-traversal 2026-05-21
CVE-2024-31848 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative…

9.8 CVSS
93.6% EPSS
path-traversal 2024-04-05
CVE-2024-31849 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative ac…

9.8 CVSS
92.2% EPSS
path-traversal 2024-04-05
CVE-2016-6600 🔴 Łataj teraz

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter t…

9.8 CVSS
90.6% EPSS
CVE-2024-31850 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive informatio…

8.6 CVSS
89.9% EPSS
path-traversal 2024-04-05
CVE-2024-24809 🟠 Łataj w tym tygodniu

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can ac…

8.5 CVSS
90.1% EPSS
path-traversalxss 2024-04-10
CVE-2024-31851 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive informati…

8.6 CVSS
89.3% EPSS
path-traversal 2024-04-05
CVE-2016-6601 🟡 Monitoruj

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/Fetch…

7.5 CVSS
92.8% EPSS
CVE-2022-31474 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

7.5 CVSS
92.3% EPSS
CVE-2016-8204 🔴 Łataj teraz
cloud

A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file sy…

9.8 CVSS
71.3% EPSS
CVE-2020-36728 ⚪ Do wiadomości

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to …

6.5 CVSS
84.4% EPSS
CVE-2013-2641 ⚪ Do wiadomości

Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.

5.0 CVSS
82.3% EPSS
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2025-1035 ⚪ Do wiadomości

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before …

5.7 CVSS
70.4% EPSS
path-traversal 2025-02-18
CVE-2014-2324 ⚪ Do wiadomości
os

Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_che…

5.0 CVSS
71.7% EPSS
CVE-2014-2314 ⚪ Do wiadomości
dev

Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

4.3 CVSS
65.8% EPSS
CVE-2009-4000 🔴 Łataj teraz

Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the …

10.0 CVSS
31.6% EPSS
hppath-traversal 2010-01-20
CVE-2013-3706 ⚪ Do wiadomości

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN…

5.0 CVSS
50.5% EPSS
CVE-2016-8205 🟠 Łataj w tym tygodniu

A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of th…

9.8 CVSS
24.1% EPSS
CVE-2024-50509 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product De…

8.6 CVSS
28.6% EPSS
path-traversal 2024-10-30
CVE-2016-6896 🟡 Monitoruj
apps

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files v…

7.1 CVSS
35.2% EPSS
CVE-2016-7982 🟡 Monitoruj

Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.

7.5 CVSS
32.7% EPSS
spippath-traversal 2017-01-18
CVE-2010-0926 ⚪ Do wiadomości

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, an…

3.5 CVSS
52.4% EPSS
sambapath-traversal 2010-03-10
CVE-2022-1476 ⚪ Do wiadomości

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, a…

6.6 CVSS
35.3% EPSS
CVE-2023-6972 🟠 Łataj w tym tygodniu

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-ide…

9.8 CVSS
19.0% EPSS
CVE-2026-39813 🟠 Łataj w tym tygodniu
network

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

9.8 CVSS
18.7% EPSS
CVE-2024-50508 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product De…

7.5 CVSS
26.3% EPSS
path-traversal 2024-10-30
CVE-2006-5028 ⚪ Do wiadomości

Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file …

5.0 CVSS
36.5% EPSS
CVE-1999-0270 ⚪ Do wiadomości

Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.

5.0 CVSS
32.4% EPSS
sgipath-traversal 1998-04-03
CVE-2026-24479 🟠 Łataj w tym tygodniu

HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize file…

9.8 CVSS
7.9% EPSS
CVE-2016-5725 ⚪ Do wiadomości

Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a r…

5.9 CVSS
26.7% EPSS
CVE-2026-38360 🟠 Łataj w tym tygodniu

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root()…

9.8 CVSS
6.5% EPSS
path-traversal 2026-05-08
CVE-2001-1586 🔴 Łataj teraz

Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vu…

10.0 CVSS
3.5% EPSS
CVE-2017-5539 🟠 Łataj w tym tygodniu

The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this attacker can exploit this vulnerability to …

9.1 CVSS
7.4% EPSS
CVE-2006-5487 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed ar…

10.0 CVSS
1.7% EPSS
CVE-2026-25895 🟠 Łataj w tym tygodniu

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server fi…

9.8 CVSS
2.7% EPSS
CVE-2026-47932 🟡 Monitoruj

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker …

8.8 CVSS
7.6% EPSS
adobepath-traversal 2026-06-09
CVE-2024-25386 🟡 Monitoruj

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

8.8 CVSS
7.2% EPSS
path-traversal 2024-03-01
CVE-2024-43955 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip droip allows Path Traversal.This issue affects Droip: from n/a through < 2.5.2.

10.0 CVSS
1.1% EPSS
CVE-2026-52813 🟠 Łataj w tym tygodniu

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path tr…

10.0 CVSS
1.1% EPSS
path-traversalrce 2026-06-24
CVE-2014-0358 🟡 Monitoruj

Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/M…

7.8 CVSS
12.0% EPSS
CVE-2014-2863 🟠 Łataj w tym tygodniu

Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.

10.0 CVSS
0.8% EPSS
CVE-2025-71338 🟠 Łataj w tym tygodniu

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fi…

10.0 CVSS
0.6% EPSS
path-traversalrce 2026-06-25
CVE-2014-2864 🟠 Łataj w tym tygodniu

Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequence…

10.0 CVSS
0.5% EPSS
CVE-2023-5241 🟠 Łataj w tym tygodniu

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to …

9.6 CVSS
2.5% EPSS
CVE-2010-0620 🔴 Łataj teraz

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitr…

9.3 CVSS
3.9% EPSS
CVE-2016-6517 🔴 Łataj teraz

Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.

9.8 CVSS
1.3% EPSS
CVE-2006-5846 ⚪ Do wiadomości

Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.

6.4 CVSS
18.3% EPSS
CVE-2026-32871 🔴 Łataj teraz

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is resp…

10.0 CVSS
0.1% EPSS
CVE-2026-7411 🟠 Łataj w tym tygodniu

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a m…

10.0 CVSS
0.1% EPSS
path-traversalrce 2026-05-05
CVE-2026-33494 🟠 Łataj w tym tygodniu

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP …

10.0 CVSS
0.1% EPSS
orypath-traversal 2026-03-26
CVE-2026-27897 🔴 Łataj teraz

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload cont…

10.0 CVSS
0.1% EPSS
CVE-2026-36767 🟠 Łataj w tym tygodniu

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

10.0 CVSS
0.1% EPSS
path-traversal 2026-04-30
CVE-2026-22557 🟠 Łataj w tym tygodniu

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying …

10.0 CVSS
0.0% EPSS
path-traversal 2026-03-19
CVE-2016-2087 🟡 Monitoruj

Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.

7.4 CVSS
13.0% EPSS
CVE-2026-33054 🔴 Łataj teraz

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI str…

10.0 CVSS
0.0% EPSS
CVE-2006-5125 ⚪ Do wiadomości

Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which tri…

5.0 CVSS
25.0% EPSS
CVE-2025-59793 🔴 Łataj teraz

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDire…

9.9 CVSS
0.5% EPSS
CVE-2025-30841 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a th…

9.9 CVSS
0.4% EPSS
path-traversal 2025-04-01
CVE-2009-4013 🟠 Łataj w tym tygodniu
os

Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vector…

9.8 CVSS
0.8% EPSS
CVE-2026-35031 🟠 Łataj w tym tygodniu

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, all…

9.9 CVSS
0.2% EPSS
CVE-2026-11420 🟠 Łataj w tym tygodniu

Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesyste…

9.8 CVSS
0.7% EPSS
CVE-2026-54414 🟠 Łataj w tym tygodniu

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename …

9.8 CVSS
0.7% EPSS
path-traversalrce 2026-06-19
CVE-2026-9559 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended tempor…

9.9 CVSS
0.2% EPSS
path-traversalrce 2026-05-29
CVE-2024-29672 🟡 Monitoruj

Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.

8.8 CVSS
5.6% EPSS
path-traversal 2024-04-05
CVE-2026-45661 🟠 Łataj w tym tygodniu

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the file…

9.9 CVSS
0.1% EPSS
path-traversalrce 2026-05-29
CVE-2026-40342 🔴 Łataj teraz

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without fi…

9.9 CVSS
0.1% EPSS
CVE-2026-42756 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.Th…

9.9 CVSS
0.1% EPSS
path-traversal 2026-05-27
CVE-2026-42757 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a…

9.9 CVSS
0.1% EPSS
path-traversal 2026-05-27
CVE-2024-8262 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal. This issue affects OBS: before 24.0927.

9.8 CVSS
0.5% EPSS
CVE-2026-36829 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled …

9.8 CVSS
0.4% EPSS
CVE-2026-11414 🟠 Łataj w tym tygodniu

A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach…

9.8 CVSS
0.4% EPSS
CVE-2014-2210 🟡 Monitoruj

Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrar…

7.5 CVSS
11.9% EPSS
cadospath-traversal 2014-04-04
CVE-2026-50869 🟠 Łataj w tym tygodniu

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

9.8 CVSS
0.3% EPSS
path-traversal 2026-06-15
CVE-2026-1830 🟠 Łataj w tym tygodniu

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code…

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-09
CVE-2026-53787 🟠 Łataj w tym tygodniu

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by …

9.8 CVSS
0.2% EPSS
CVE-2026-42249 🔴 Łataj teraz 🇵🇱 CERT.pl
appscloud

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local …

9.8 CVSS
0.2% EPSS
CVE-2026-22562 🟠 Łataj w tym tygodniu

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affec…

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-13
CVE-2026-37531 🟠 Łataj w tym tygodniu

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.…

9.8 CVSS
0.2% EPSS
CVE-2026-6057 🟠 Łataj w tym tygodniu

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-10
CVE-2026-2743 🟠 Łataj w tym tygodniu

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

9.8 CVSS
0.2% EPSS
CVE-2023-6190 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal. This issue affects U…

9.8 CVSS
0.2% EPSS
ikcupath-traversal 2023-12-27
CVE-2025-69874 🔴 Łataj teraz

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containi…

9.8 CVSS
0.1% EPSS
CVE-2026-35471 🔴 Łataj teraz

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.

9.8 CVSS
0.1% EPSS
CVE-2026-6074 🟠 Łataj w tym tygodniu

Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name p…

9.8 CVSS
0.1% EPSS
path-traversal 2026-04-23
CVE-2026-4619 🟠 Łataj w tym tygodniu

Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

9.8 CVSS
0.1% EPSS
necpath-traversal 2026-03-27
CVE-2026-32771 🔴 Łataj teraz

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/ex…

9.8 CVSS
0.0% EPSS
CVE-2026-33195 🟠 Łataj w tym tygodniu

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem p…

9.8 CVSS
0.0% EPSS
CVE-2023-6699 🟠 Łataj w tym tygodniu

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated att…

9.1 CVSS
3.4% EPSS
CVE-2006-5733 🟡 Monitoruj

Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by …

7.5 CVSS
11.2% EPSS
CVE-2024-49286 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Events ssv-events allows PHP Local File Inclusion.This issue affects SSV Events: from n/a through <= 3.2…

9.6 CVSS
0.7% EPSS
CVE-2024-44014 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager allows PHP Local File Inclusion.This issue affects Vmax Project Manage…

9.6 CVSS
0.6% EPSS
lfipath-traversal 2024-10-05
CVE-2026-52703 🟠 Łataj w tym tygodniu

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

9.6 CVSS
0.4% EPSS
path-traversal 2026-06-15
CVE-2026-53476 🟠 Łataj w tym tygodniu

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the a…

9.6 CVSS
0.3% EPSS
CVE-2026-28373 🔴 Łataj teraz
os

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary con…

9.6 CVSS
0.1% EPSS
CVE-2026-41589 🔴 Łataj teraz

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client ca…

9.6 CVSS
0.1% EPSS
CVE-2025-15036 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v…

9.6 CVSS
0.1% EPSS
path-traversal 2026-03-30
CVE-2026-5166 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pa…

9.6 CVSS
0.0% EPSS
path-traversal 2026-04-29
CVE-2026-36760 🟠 Łataj w tym tygodniu

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffi…

9.6 CVSS
0.0% EPSS
path-traversal 2026-04-30
CVE-2026-42048 🔴 Łataj teraz

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because use…

9.6 CVSS
0.0% EPSS
CVE-2026-33211 🟠 Łataj w tym tygodniu

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vuln…

9.6 CVSS
0.0% EPSS
CVE-2026-48866 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

9.6 CVSS
0.0% EPSS
path-traversal 2026-06-01
CVE-2016-8206 🟡 Monitoruj

A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently…

7.5 CVSS
10.4% EPSS
CVE-2026-2493 🟡 Monitoruj

IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not req…

7.5 CVSS
10.3% EPSS
path-traversal 2026-03-16
CVE-2023-5414 🟠 Łataj w tym tygodniu

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbi…

9.1 CVSS
2.1% EPSS
CVE-2026-41948 🔴 Łataj teraz

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitizat…

9.4 CVSS
0.5% EPSS
CVE-2006-5596 🟡 Monitoruj

Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

7.5 CVSS
9.8% EPSS
CVE-2016-6269 🔴 Łataj teraz

Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via th…

9.1 CVSS
1.8% EPSS
CVE-2014-0632 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.

9.0 CVSS
2.3% EPSS
emcpath-traversal 2014-04-01
CVE-2014-1507 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted applicatio…

9.3 CVSS
0.7% EPSS
CVE-2026-42882 🟠 Łataj w tym tygodniu

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler…

9.4 CVSS
0.1% EPSS
CVE-2026-41448 🟠 Łataj w tym tygodniu

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token…

9.4 CVSS
0.1% EPSS
CVE-2024-39619 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <=…

9.0 CVSS
1.7% EPSS
CVE-2025-41268 🟠 Łataj w tym tygodniu

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbi…

9.1 CVSS
1.1% EPSS
CVE-2024-24042 🟡 Monitoruj

Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirect in RuntimeResourcePackImpl component.

8.8 CVSS
2.6% EPSS
path-traversal 2024-03-19
CVE-2022-4030 🟡 Monitoruj

The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attac…

8.1 CVSS
6.0% EPSS
CVE-2024-7387 🟠 Łataj w tym tygodniu

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using…

9.1 CVSS
0.8% EPSS
path-traversalrce 2024-09-17
CVE-2026-50203 🟠 Łataj w tym tygodniu
apps

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via c…

9.1 CVSS
0.7% EPSS
CVE-2024-47637 🟡 Monitoruj

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

8.8 CVSS
2.2% EPSS
CVE-2026-35174 🟠 Łataj w tym tygodniu

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change t…

9.1 CVSS
0.5% EPSS
CVE-2024-28335 🟠 Łataj w tym tygodniu

Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses Ja…

9.1 CVSS
0.4% EPSS
path-traversal 2024-03-27
CVE-2025-55017 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to …

9.1 CVSS
0.4% EPSS
path-traversal 2026-06-26
CVE-2025-64152 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to …

9.1 CVSS
0.4% EPSS
path-traversal 2026-06-26
CVE-2026-35573 🔴 Łataj teraz

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve r…

9.1 CVSS
0.3% EPSS
CVE-2026-45230 🟠 Łataj w tym tygodniu

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ …

9.1 CVSS
0.3% EPSS
dospath-traversal 2026-05-18
CVE-2026-36500 🟠 Łataj w tym tygodniu

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.

9.1 CVSS
0.3% EPSS
path-traversal 2026-06-05
CVE-2026-40982 🟠 Łataj w tym tygodniu

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lea…

9.1 CVSS
0.1% EPSS
path-traversal 2026-05-07
CVE-2026-42608 🔴 Łataj teraz

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unaut…

9.1 CVSS
0.1% EPSS
CVE-2026-7302 🟠 Łataj w tym tygodniu

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequenc…

9.1 CVSS
0.1% EPSS
lmsyspath-traversal 2026-05-18
CVE-2026-40258 🟠 Łataj w tym tygodniu

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. An authenticated us…

9.1 CVSS
0.1% EPSS
path-traversal 2026-04-17
CVE-2026-39847 🟠 Łataj w tym tygodniu

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attac…

9.1 CVSS
0.1% EPSS
CVE-2006-5510 ⚪ Do wiadomości

Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, as demonstrated by uploading a .gif fil…

6.4 CVSS
13.6% EPSS
CVE-2026-33183 🟠 Łataj w tym tygodniu

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file paths under the configured fixture directory without validation. A name con…

9.1 CVSS
0.0% EPSS
CVE-2024-52396 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3.

8.8 CVSS
1.3% EPSS
CVE-2009-4645 🟡 Monitoruj

Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

7.8 CVSS
6.3% EPSS
CVE-2026-3838 🟡 Monitoruj

Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit th…

8.8 CVSS
1.2% EPSS
CVE-2026-4092 🟡 Monitoruj
cloud

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequ…

8.8 CVSS
1.1% EPSS
CVE-2026-40128 🟠 Łataj w tym tygodniu

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the i…

9.0 CVSS
0.1% EPSS
path-traversal 2026-06-09
CVE-2026-36723 🟡 Monitoruj

An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbi…

8.8 CVSS
1.1% EPSS
path-traversalrce 2026-06-09
CVE-2025-66074 🟠 Łataj w tym tygodniu

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8.

9.0 CVSS
0.1% EPSS
path-traversal 2025-12-18
CVE-2026-30893 🟠 Łataj w tym tygodniu

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction rout…

9.0 CVSS
0.1% EPSS
wazuhpath-traversal 2026-04-29
CVE-2026-39305 🔴 Łataj teraz

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the…

9.0 CVSS
0.1% EPSS
CVE-2026-24486 🟠 Łataj w tym tygodniu

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An at…

8.6 CVSS
1.8% EPSS
CVE-2026-25161 🟠 Łataj w tym tygodniu

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation handlers. An authenticat…

8.8 CVSS
0.7% EPSS
CVE-2026-56078 🟡 Monitoruj

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, wr…

8.8 CVSS
0.7% EPSS
dospath-traversal 2026-06-18
CVE-2026-25059 🟠 Łataj w tym tygodniu

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability in multiple file operation handlers in server/handles/fsmanage.go. Filename components in req.Names…

8.8 CVSS
0.6% EPSS
CVE-2026-57296 🟡 Monitoruj

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permiss…

8.8 CVSS
0.6% EPSS
path-traversalrce 2026-06-24
CVE-2006-5263 🟡 Monitoruj

Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated…

7.5 CVSS
7.0% EPSS
CVE-2026-11419 🟡 Monitoruj

A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. An authenticated user can supp…

8.8 CVSS
0.5% EPSS
CVE-2006-5866 ⚪ Do wiadomości

Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.

6.4 CVSS
12.4% EPSS
CVE-2026-42605 🟠 Łataj w tym tygodniu

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not…

8.8 CVSS
0.4% EPSS
CVE-2026-40076 🟠 Łataj w tym tygodniu

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a…

8.8 CVSS
0.4% EPSS
CVE-2026-42661 🟡 Monitoruj

Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.

8.8 CVSS
0.4% EPSS
path-traversal 2026-06-15
CVE-2026-32060 🟡 Monitoruj

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without fi…

8.8 CVSS
0.4% EPSS
CVE-2009-2693 ⚪ Do wiadomości
apps

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrate…

5.8 CVSS
15.3% EPSS
CVE-2026-50016 🟠 Łataj w tym tygodniu

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesys…

8.8 CVSS
0.3% EPSS
CVE-2026-32193 🟡 Monitoruj
appscloud

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

8.8 CVSS
0.3% EPSS
CVE-2025-67030 🟡 Monitoruj

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

8.8 CVSS
0.3% EPSS
CVE-2026-25559 🟡 Monitoruj

OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete operations by supplying unsanitized…

8.8 CVSS
0.3% EPSS
path-traversalrce 2026-06-08
CVE-2006-5554 🟡 Monitoruj

Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter…

7.5 CVSS
6.7% EPSS
CVE-2026-39981 🟠 Łataj w tym tygodniu

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An a…

8.8 CVSS
0.2% EPSS
CVE-2024-39624 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.

8.5 CVSS
1.7% EPSS
CVE-2026-24217 🟡 Monitoruj
os

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, in…

8.8 CVSS
0.1% EPSS
CVE-2026-27040 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31.

8.8 CVSS
0.1% EPSS
path-traversal 2026-03-25
CVE-2026-33686 🟡 Monitoruj

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, all…

8.8 CVSS
0.1% EPSS
CVE-2026-5027 🟡 Monitoruj

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../…

8.8 CVSS
0.1% EPSS
path-traversal 2026-03-27
CVE-2026-44239 🟡 Monitoruj

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter …

8.8 CVSS
0.1% EPSS
CVE-2026-35397 🟠 Łataj w tym tygodniu

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling…

8.8 CVSS
0.0% EPSS
CVE-2022-45829 🟡 Monitoruj

Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.

8.7 CVSS
0.5% EPSS
CVE-2026-3666 🟡 Monitoruj

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes…

8.8 CVSS
0.0% EPSS
path-traversal 2026-04-04
CVE-2026-36762 🟡 Monitoruj

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted …

8.8 CVSS
0.0% EPSS
path-traversal 2026-04-30
CVE-2026-7474 🟡 Monitoruj

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

8.8 CVSS
0.0% EPSS
path-traversal 2026-05-12
CVE-2026-25707 🟡 Monitoruj

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service…

8.8 CVSS
0.0% EPSS
CVE-2026-40521 🟡 Monitoruj

FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the uniq…

8.8 CVSS
0.0% EPSS
path-traversalrce 2026-06-29
CVE-2010-0759 🟡 Monitoruj

Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and …

7.5 CVSS
6.4% EPSS
CVE-2006-5894 ⚪ Do wiadomości

Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as…

6.8 CVSS
9.8% EPSS
CVE-2009-4679 🟡 Monitoruj

Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller …

7.5 CVSS
6.3% EPSS
CVE-2026-34728 🟠 Łataj w tym tygodniu

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied n…

8.7 CVSS
0.2% EPSS
CVE-2026-35214 🟠 Łataj w tym tygodniu

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path tr…

8.7 CVSS
0.1% EPSS
CVE-2026-42275 🟡 Monitoruj

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent s…

8.7 CVSS
0.0% EPSS
CVE-2026-34653 🟡 Monitoruj

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that co…

8.7 CVSS
0.0% EPSS
adobepath-traversal 2026-05-12
CVE-2026-25635 🟠 Łataj w tym tygodniu

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS…

8.6 CVSS
0.4% EPSS
CVE-2024-49253 🟡 Monitoruj

Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.

8.6 CVSS
0.4% EPSS
path-traversal 2024-10-16
CVE-2026-49991 🟡 Monitoruj

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract…

8.6 CVSS
0.3% EPSS
path-traversal 2026-06-26
CVE-2025-4123 🟡 Monitoruj

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will exec…

7.6 CVSS
5.3% EPSS
CVE-2024-49315 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n…

8.6 CVSS
0.2% EPSS
path-traversal 2024-10-17
CVE-2012-10024 ⚪ Do wiadomości

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request…

0.0 CVSS
43.2% EPSS
path-traversal 2025-08-05