CVE z tagiem path-traversal — 200 wyników. ← Wszystkie tagi

CVE-2019-19781 🔴 Łataj teraz KEV

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

9.8 CVSS
100.0% EPSS
CVE-2010-2861 🔴 Łataj teraz KEV

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/…

9.8 CVSS
99.7% EPSS
CVE-2023-47246 🔴 Łataj teraz KEV

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

9.8 CVSS
98.9% EPSS
CVE-2024-41713 🔴 Łataj teraz KEV

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input val…

9.1 CVSS
98.1% EPSS
mitelpath-traversal 2024-10-21
CVE-2025-8088 🔴 Łataj teraz KEV
appscloud

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered b…

8.8 CVSS
94.5% EPSS
CVE-2014-0780 🔴 Łataj teraz KEV

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecifi…

9.8 CVSS
89.3% EPSS
CVE-2022-37042 🔴 Łataj teraz KEV

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arb…

9.8 CVSS
88.8% EPSS
CVE-2020-3452 🔴 Łataj teraz KEV
network

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory tra…

7.5 CVSS
100.0% EPSS
CVE-2018-0296 🔴 Łataj teraz KEV
network

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do…

7.5 CVSS
99.9% EPSS
CVE-2022-30333 🔴 Łataj teraz KEV
os

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR ar…

7.5 CVSS
99.1% EPSS
CVE-2018-20250 🔴 Łataj teraz KEV

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, th…

7.8 CVSS
96.3% EPSS
CVE-2022-27925 🔴 Łataj teraz KEV

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files…

7.2 CVSS
98.6% EPSS
CVE-2024-57727 🔴 Łataj teraz KEV

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted …

7.5 CVSS
95.2% EPSS
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2017-12637 🔴 Łataj teraz KEV

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string…

7.5 CVSS
93.5% EPSS
sappath-traversal 2017-08-07
CVE-2015-3035 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0…

7.5 CVSS
93.1% EPSS
CVE-2016-0752 🔴 Łataj teraz KEV

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by le…

7.5 CVSS
91.0% EPSS
CVE-2024-27199 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

7.3 CVSS
92.0% EPSS
CVE-2015-4068 🔴 Łataj teraz KEV

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) expor…

9.1 CVSS
80.4% EPSS
CVE-2023-41266 🔴 Łataj teraz KEV

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and ear…

8.2 CVSS
82.1% EPSS
qlikpath-traversal 2023-08-29
CVE-2023-38950 🔴 Łataj teraz KEV

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19…

7.5 CVSS
84.9% EPSS
CVE-2016-3976 🔴 Łataj teraz KEV

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Secu…

7.5 CVSS
76.3% EPSS
CVE-2015-0666 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

7.5 CVSS
58.5% EPSS
ciscopath-traversal 2015-04-03
CVE-2014-0130 🔴 Łataj teraz KEV

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbin…

7.5 CVSS
57.0% EPSS
CVE-2026-48282 🔴 Łataj teraz KEV

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context o…

10.0 CVSS
42.4% EPSS
CVE-2026-34909 🔴 Łataj teraz KEV

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

10.0 CVSS
2.3% EPSS
CVE-2026-59310 🔴 Łataj teraz KEV
cloud

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

9.8 CVSS
2.4% EPSS
CVE-2026-34926 🔴 Łataj teraz KEV

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installa…

6.7 CVSS
12.7% EPSS
CVE-2024-11667 🔴 Łataj teraz KEV
network

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware version…

7.5 CVSS
3.0% EPSS
zyxelpath-traversal 2024-11-27
CVE-2025-2749 🔴 Łataj teraz KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, in…

7.2 CVSS
3.5% EPSS
CVE-2024-31848 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative…

9.8 CVSS
93.6% EPSS
path-traversal 2024-04-05
CVE-2020-3187 🔴 Łataj teraz
network

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory tra…

9.1 CVSS
96.6% EPSS
CVE-2024-31849 🔴 Łataj teraz

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative ac…

9.8 CVSS
92.2% EPSS
path-traversal 2024-04-05
CVE-2016-6600 🔴 Łataj teraz

Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter t…

9.8 CVSS
90.6% EPSS
CVE-2024-31850 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive informatio…

8.6 CVSS
89.9% EPSS
path-traversal 2024-04-05
CVE-2024-24809 🟠 Łataj w tym tygodniu

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can ac…

8.5 CVSS
90.1% EPSS
path-traversalxss 2024-04-10
CVE-2024-31851 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive informati…

8.6 CVSS
89.3% EPSS
path-traversal 2024-04-05
CVE-2016-6601 🟡 Monitoruj

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/Fetch…

7.5 CVSS
92.8% EPSS
CVE-2022-31474 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

7.5 CVSS
92.3% EPSS
CVE-2016-8204 🔴 Łataj teraz
cloud

A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file sy…

9.8 CVSS
71.3% EPSS
CVE-2020-36728 ⚪ Do wiadomości

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to …

6.5 CVSS
84.4% EPSS
CVE-2013-2641 ⚪ Do wiadomości

Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.

5.0 CVSS
82.3% EPSS
CVE-2023-2745 ⚪ Do wiadomości
apps

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where…

5.4 CVSS
79.5% EPSS
CVE-2025-1035 ⚪ Do wiadomości

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before …

5.7 CVSS
70.4% EPSS
path-traversal 2025-02-18
CVE-2015-7601 🟡 Monitoruj

Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.

7.8 CVSS
58.3% EPSS
CVE-2014-2324 ⚪ Do wiadomości
os

Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_che…

5.0 CVSS
71.7% EPSS
CVE-2014-2314 ⚪ Do wiadomości
dev

Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

4.3 CVSS
65.8% EPSS
CVE-2009-4000 🔴 Łataj teraz

Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the …

10.0 CVSS
31.6% EPSS
hppath-traversal 2010-01-20
CVE-2026-5027 🟠 Łataj w tym tygodniu

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../…

8.8 CVSS
33.3% EPSS
CVE-2013-3706 ⚪ Do wiadomości

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN…

5.0 CVSS
50.5% EPSS
CVE-2016-8205 🟠 Łataj w tym tygodniu

A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of th…

9.8 CVSS
24.1% EPSS
CVE-2026-48319 🟠 Łataj w tym tygodniu

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with…

9.1 CVSS
27.0% EPSS
CVE-2026-27305 🟠 Łataj w tym tygodniu

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker c…

8.6 CVSS
29.0% EPSS
adobepath-traversal 2026-04-14
CVE-2024-50509 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product De…

8.6 CVSS
28.6% EPSS
path-traversal 2024-10-30
CVE-2016-6896 🟡 Monitoruj
apps

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files v…

7.1 CVSS
35.2% EPSS
CVE-2016-7982 🟡 Monitoruj

Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.

7.5 CVSS
32.7% EPSS
spippath-traversal 2017-01-18
CVE-2010-0926 ⚪ Do wiadomości

The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, an…

3.5 CVSS
52.4% EPSS
sambapath-traversal 2010-03-10
CVE-2022-1476 ⚪ Do wiadomości

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, a…

6.6 CVSS
35.3% EPSS
CVE-2023-6972 🟠 Łataj w tym tygodniu

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-ide…

9.8 CVSS
19.0% EPSS
CVE-2026-39813 🟠 Łataj w tym tygodniu
network

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

9.8 CVSS
18.7% EPSS
CVE-2024-50508 🟡 Monitoruj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product De…

7.5 CVSS
26.3% EPSS
path-traversal 2024-10-30
CVE-2006-5028 ⚪ Do wiadomości

Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file …

5.0 CVSS
36.5% EPSS
CVE-2024-6127 🟠 Łataj w tym tygodniu

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, com…

9.8 CVSS
10.3% EPSS
path-traversalrce 2024-06-27
CVE-1999-0270 ⚪ Do wiadomości

Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.

5.0 CVSS
32.4% EPSS
sgipath-traversal 1998-04-03
CVE-2026-24479 🟠 Łataj w tym tygodniu

HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize file…

9.8 CVSS
7.9% EPSS
CVE-2026-48318 🟠 Łataj w tym tygodniu

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to acc…

9.9 CVSS
7.0% EPSS
adobepath-traversal 2026-07-14
CVE-2016-5725 ⚪ Do wiadomości

Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a r…

5.9 CVSS
26.7% EPSS
CVE-2026-38360 🟠 Łataj w tym tygodniu

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root()…

9.8 CVSS
6.5% EPSS
path-traversal 2026-05-08
CVE-2001-1586 🔴 Łataj teraz

Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vu…

10.0 CVSS
3.5% EPSS
CVE-2017-5539 🟠 Łataj w tym tygodniu

The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this attacker can exploit this vulnerability to …

9.1 CVSS
7.4% EPSS
CVE-2026-34415 🟠 Łataj w tym tygodniu

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex patter…

9.8 CVSS
3.6% EPSS
CVE-2024-48884 🟡 Monitoruj
network

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, Forti…

7.5 CVSS
14.9% EPSS
CVE-2023-38951 🟠 Łataj w tym tygodniu

ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path tr…

9.8 CVSS
3.3% EPSS
CVE-2006-5487 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed ar…

10.0 CVSS
1.7% EPSS
CVE-2026-25895 🟠 Łataj w tym tygodniu

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server fi…

9.8 CVSS
2.7% EPSS
CVE-2024-25386 🟡 Monitoruj

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

8.8 CVSS
7.2% EPSS
path-traversal 2024-03-01
CVE-2024-43955 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip droip allows Path Traversal.This issue affects Droip: from n/a through < 2.5.2.

10.0 CVSS
1.1% EPSS
CVE-2026-52813 🟠 Łataj w tym tygodniu

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path tr…

10.0 CVSS
1.1% EPSS
path-traversalrce 2026-06-24
CVE-2026-32871 🔴 Łataj teraz

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is resp…

10.0 CVSS
1.0% EPSS
CVE-2024-24398 🔴 Łataj teraz

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

9.8 CVSS
2.0% EPSS
CVE-2017-15681 🟠 Łataj w tym tygodniu

In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.

9.8 CVSS
2.0% EPSS
CVE-2014-0358 🟡 Monitoruj

Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/M…

7.8 CVSS
12.0% EPSS
CVE-2020-26037 🟠 Łataj w tym tygodniu

Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.

9.8 CVSS
1.8% EPSS
CVE-2014-2863 🟠 Łataj w tym tygodniu

Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.

10.0 CVSS
0.8% EPSS
CVE-2025-71338 🔴 Łataj teraz

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fi…

10.0 CVSS
0.6% EPSS
CVE-2022-28945 🔴 Łataj teraz

An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.

9.8 CVSS
1.6% EPSS
CVE-2025-15036 🔴 Łataj teraz

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v…

10.0 CVSS
0.6% EPSS
CVE-2014-2864 🟠 Łataj w tym tygodniu

Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequence…

10.0 CVSS
0.5% EPSS
CVE-2023-5241 🟠 Łataj w tym tygodniu

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to …

9.6 CVSS
2.5% EPSS
CVE-2026-27606 🔴 Łataj teraz

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Tra…

9.8 CVSS
1.4% EPSS
CVE-2010-0620 🔴 Łataj teraz

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitr…

9.3 CVSS
3.9% EPSS
CVE-2024-33109 🟠 Łataj w tym tygodniu

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

9.9 CVSS
0.9% EPSS
CVE-2024-46446 🔴 Łataj teraz

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbit…

9.8 CVSS
1.4% EPSS
CVE-2016-6517 🔴 Łataj teraz

Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.

9.8 CVSS
1.3% EPSS
CVE-2026-36829 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled …

9.8 CVSS
1.3% EPSS
CVE-2026-65700 🟠 Łataj w tym tygodniu

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by …

9.8 CVSS
1.3% EPSS
path-traversalrce 2026-07-23
CVE-2006-5846 ⚪ Do wiadomości

Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.

6.4 CVSS
18.3% EPSS
CVE-2026-45661 🟠 Łataj w tym tygodniu

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the file…

9.9 CVSS
0.7% EPSS
path-traversalrce 2026-05-29
CVE-2026-63509 🟠 Łataj w tym tygodniu

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

9.9 CVSS
0.6% EPSS
path-traversal 2026-08-20
CVE-2026-7411 🟠 Łataj w tym tygodniu

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a m…

10.0 CVSS
0.1% EPSS
path-traversalrce 2026-05-05
CVE-2026-44024 🟠 Łataj w tym tygodniu

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, an…

9.8 CVSS
1.1% EPSS
CVE-2026-9559 🟠 Łataj w tym tygodniu

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended tempor…

9.9 CVSS
0.6% EPSS
path-traversalrce 2026-05-29
CVE-2026-33494 🟠 Łataj w tym tygodniu

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP …

10.0 CVSS
0.1% EPSS
orypath-traversal 2026-03-26
CVE-2026-27897 🔴 Łataj teraz

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload cont…

10.0 CVSS
0.1% EPSS
CVE-2026-36767 🟠 Łataj w tym tygodniu

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

10.0 CVSS
0.1% EPSS
path-traversal 2026-04-30
CVE-2026-57401 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.

9.9 CVSS
0.5% EPSS
path-traversal 2026-07-13
CVE-2026-22557 🟠 Łataj w tym tygodniu

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying …

10.0 CVSS
0.0% EPSS
path-traversal 2026-03-19
CVE-2016-2087 🟡 Monitoruj

Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.

7.4 CVSS
13.0% EPSS
CVE-2026-33054 🔴 Łataj teraz

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI str…

10.0 CVSS
0.0% EPSS
CVE-2006-5125 ⚪ Do wiadomości

Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which tri…

5.0 CVSS
25.0% EPSS
CVE-2025-59793 🔴 Łataj teraz

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDire…

9.9 CVSS
0.5% EPSS
CVE-2026-47429 🔴 Łataj teraz

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read fil…

9.8 CVSS
0.9% EPSS
CVE-2025-30841 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a th…

9.9 CVSS
0.4% EPSS
path-traversal 2025-04-01
CVE-2009-4013 🟠 Łataj w tym tygodniu
os

Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vector…

9.8 CVSS
0.8% EPSS
CVE-2026-8859 🟠 Łataj w tym tygodniu
os

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists …

9.9 CVSS
0.3% EPSS
applepath-traversal 2026-07-17
CVE-2026-52680 🟠 Łataj w tym tygodniu
apps

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path…

9.8 CVSS
0.8% EPSS
CVE-2026-35031 🟠 Łataj w tym tygodniu

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, all…

9.9 CVSS
0.2% EPSS
CVE-2026-11420 🟠 Łataj w tym tygodniu

Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesyste…

9.8 CVSS
0.7% EPSS
CVE-2026-53451 🟠 Łataj w tym tygodniu

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attac…

9.8 CVSS
0.7% EPSS
path-traversal 2026-08-19
CVE-2026-35471 🔴 Łataj teraz

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.

9.8 CVSS
0.7% EPSS
CVE-2026-54414 🟠 Łataj w tym tygodniu

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename …

9.8 CVSS
0.7% EPSS
path-traversal 2026-06-19
CVE-2024-29672 🟡 Monitoruj

Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.

8.8 CVSS
5.6% EPSS
path-traversal 2024-04-05
CVE-2025-71333 🔴 Łataj teraz

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowI…

9.8 CVSS
0.6% EPSS
CVE-2026-65688 🟠 Łataj w tym tygodniu

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server fil…

9.8 CVSS
0.6% EPSS
CVE-2026-40342 🔴 Łataj teraz

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without fi…

9.9 CVSS
0.1% EPSS
CVE-2026-65689 🟠 Łataj w tym tygodniu

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server f…

9.8 CVSS
0.6% EPSS
CVE-2026-65687 🟠 Łataj w tym tygodniu

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server file…

9.8 CVSS
0.6% EPSS
CVE-2026-33195 🟠 Łataj w tym tygodniu

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem p…

9.8 CVSS
0.6% EPSS
CVE-2026-42756 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.Th…

9.9 CVSS
0.1% EPSS
path-traversal 2026-05-27
CVE-2026-42757 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a…

9.9 CVSS
0.1% EPSS
path-traversal 2026-05-27
CVE-2022-23347 🟡 Monitoruj

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

7.5 CVSS
12.0% EPSS
CVE-2024-8262 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal. This issue affects OBS: before 24.0927.

9.8 CVSS
0.5% EPSS
CVE-2026-48313 🟠 Łataj w tym tygodniu

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited wr…

9.3 CVSS
2.9% EPSS
adobepath-traversal 2026-06-30
CVE-2026-47627 🟠 Łataj w tym tygodniu

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.

9.8 CVSS
0.4% EPSS
dospath-traversal 2026-08-18
CVE-2026-11414 🟠 Łataj w tym tygodniu

A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach…

9.8 CVSS
0.4% EPSS
CVE-2014-2210 🟡 Monitoruj

Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrar…

7.5 CVSS
11.9% EPSS
cadospath-traversal 2014-04-04
CVE-2026-50869 🟠 Łataj w tym tygodniu

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

9.8 CVSS
0.3% EPSS
path-traversal 2026-06-15
CVE-2026-1830 🟠 Łataj w tym tygodniu

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code…

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-09
CVE-2026-53787 🟠 Łataj w tym tygodniu

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by …

9.8 CVSS
0.2% EPSS
CVE-2026-42249 🔴 Łataj teraz 🇵🇱 CERT.pl
appscloud

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local …

9.8 CVSS
0.2% EPSS
CVE-2026-22562 🟠 Łataj w tym tygodniu

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affec…

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-13
CVE-2026-37531 🟠 Łataj w tym tygodniu

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.…

9.8 CVSS
0.2% EPSS
CVE-2026-6057 🟠 Łataj w tym tygodniu

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

9.8 CVSS
0.2% EPSS
path-traversalrce 2026-04-10
CVE-2026-2743 🟠 Łataj w tym tygodniu

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

9.8 CVSS
0.2% EPSS
CVE-2023-6190 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal. This issue affects U…

9.8 CVSS
0.2% EPSS
ikcupath-traversal 2023-12-27
CVE-2025-69874 🔴 Łataj teraz

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containi…

9.8 CVSS
0.1% EPSS
CVE-2026-6074 🟠 Łataj w tym tygodniu

Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name p…

9.8 CVSS
0.1% EPSS
path-traversal 2026-04-23
CVE-2026-4619 🟠 Łataj w tym tygodniu

Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

9.8 CVSS
0.1% EPSS
necpath-traversal 2026-03-27
CVE-2026-32771 🔴 Łataj teraz

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/ex…

9.8 CVSS
0.0% EPSS
CVE-2023-6699 🟠 Łataj w tym tygodniu

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated att…

9.1 CVSS
3.4% EPSS
CVE-2006-5733 🟡 Monitoruj

Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by …

7.5 CVSS
11.2% EPSS
CVE-2024-49286 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Events ssv-events allows PHP Local File Inclusion.This issue affects SSV Events: from n/a through <= 3.2…

9.6 CVSS
0.7% EPSS
CVE-2024-44014 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager allows PHP Local File Inclusion.This issue affects Vmax Project Manage…

9.6 CVSS
0.6% EPSS
lfipath-traversal 2024-10-05
CVE-2026-33211 🟠 Łataj w tym tygodniu

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vuln…

9.6 CVSS
0.6% EPSS
CVE-2026-69400 🟠 Łataj w tym tygodniu

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

9.6 CVSS
0.6% EPSS
path-traversal 2026-08-20
CVE-2019-10869 🟠 Łataj w tym tygodniu

Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and exe…

8.1 CVSS
8.0% EPSS
CVE-2026-28373 🔴 Łataj teraz
os

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary con…

9.6 CVSS
0.4% EPSS
CVE-2026-59792 🟠 Łataj w tym tygodniu

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

9.6 CVSS
0.4% EPSS
CVE-2026-52703 🟠 Łataj w tym tygodniu

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

9.6 CVSS
0.4% EPSS
path-traversal 2026-06-15
CVE-2026-53476 🟠 Łataj w tym tygodniu

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the a…

9.6 CVSS
0.3% EPSS
CVE-2026-41589 🔴 Łataj teraz

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client ca…

9.6 CVSS
0.1% EPSS
CVE-2026-5166 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pa…

9.6 CVSS
0.0% EPSS
path-traversal 2026-04-29
CVE-2026-36760 🟠 Łataj w tym tygodniu

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffi…

9.6 CVSS
0.0% EPSS
path-traversal 2026-04-30
CVE-2026-42048 🔴 Łataj teraz

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because use…

9.6 CVSS
0.0% EPSS
CVE-2026-48866 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

9.6 CVSS
0.0% EPSS
path-traversal 2026-06-01
CVE-2016-8206 🟡 Monitoruj

A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently…

7.5 CVSS
10.4% EPSS
CVE-2024-7387 🟠 Łataj w tym tygodniu

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using…

9.1 CVSS
2.3% EPSS
path-traversalrce 2024-09-17
CVE-2026-2493 🟡 Monitoruj

IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not req…

7.5 CVSS
10.3% EPSS
path-traversal 2026-03-16
CVE-2023-5414 🟠 Łataj w tym tygodniu

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbi…

9.1 CVSS
2.1% EPSS
CVE-2026-9312 🟡 Monitoruj
dev

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input valida…

8.2 CVSS
6.6% EPSS
CVE-2026-41948 🔴 Łataj teraz

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitizat…

9.4 CVSS
0.5% EPSS
CVE-2006-5596 🟡 Monitoruj

Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

7.5 CVSS
9.8% EPSS
CVE-2016-6269 🔴 Łataj teraz

Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via th…

9.1 CVSS
1.8% EPSS
CVE-2014-0632 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.

9.0 CVSS
2.3% EPSS
emcpath-traversal 2014-04-01
CVE-2014-1507 🟠 Łataj w tym tygodniu

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted applicatio…

9.3 CVSS
0.7% EPSS
CVE-2026-42882 🟠 Łataj w tym tygodniu

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler…

9.4 CVSS
0.1% EPSS
CVE-2026-41448 🟠 Łataj w tym tygodniu

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token…

9.4 CVSS
0.1% EPSS
CVE-2026-17181 🟠 Łataj w tym tygodniu

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

9.3 CVSS
0.5% EPSS
ibmpath-traversal 2026-08-14
CVE-2023-24188 🔴 Łataj teraz

ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

9.1 CVSS
1.2% EPSS
CVE-2024-39619 🟠 Łataj w tym tygodniu

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <=…

9.0 CVSS
1.7% EPSS
CVE-2024-24042 🟡 Monitoruj

Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirect in RuntimeResourcePackImpl component.

8.8 CVSS
2.6% EPSS
path-traversal 2024-03-19
CVE-2026-47932 🟡 Monitoruj

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context…

8.8 CVSS
2.5% EPSS
CVE-2022-4030 🟡 Monitoruj

The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attac…

8.1 CVSS
6.0% EPSS
CVE-2026-52610 🟠 Łataj w tym tygodniu

An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying…

9.1 CVSS
0.8% EPSS
path-traversal 2026-08-18
CVE-2025-55526 🔴 Łataj teraz

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

9.1 CVSS
0.8% EPSS
CVE-2026-9725 🟠 Łataj w tym tygodniu

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_d…

9.1 CVSS
0.7% EPSS
path-traversalrce 2026-07-03
CVE-2026-40982 🟠 Łataj w tym tygodniu
cloud

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lea…

9.1 CVSS
0.7% EPSS
CVE-2026-50203 🟠 Łataj w tym tygodniu
apps

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via c…

9.1 CVSS
0.7% EPSS
CVE-2024-47637 🟡 Monitoruj

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

8.8 CVSS
2.2% EPSS
CVE-2026-53976 🟠 Łataj w tym tygodniu

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the a…

9.1 CVSS
0.7% EPSS
CVE-2026-45230 🟠 Łataj w tym tygodniu

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ …

9.1 CVSS
0.6% EPSS
dospath-traversal 2026-05-18
CVE-2026-58166 🟠 Łataj w tym tygodniu

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by supplying a malicious multipart filename …

9.1 CVSS
0.6% EPSS
path-traversal 2026-06-30
CVE-2026-35174 🟠 Łataj w tym tygodniu

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change t…

9.1 CVSS
0.6% EPSS
CVE-2026-15265 🟠 Łataj w tym tygodniu

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

9.1 CVSS
0.6% EPSS
CVE-2026-39847 🟠 Łataj w tym tygodniu

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attac…

9.1 CVSS
0.5% EPSS
CVE-2026-17556 🟠 Łataj w tym tygodniu
dev

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory co…

9.1 CVSS
0.5% EPSS
CVE-2026-3141 🟠 Łataj w tym tygodniu

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and includ…

9.1 CVSS
0.5% EPSS
path-traversal 2026-08-01
CVE-2025-41268 🟠 Łataj w tym tygodniu

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbi…

9.1 CVSS
0.4% EPSS
CVE-2026-43637 🟠 Łataj w tym tygodniu

Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a crafted TAR archive containing ../ sequences, abso…

9.1 CVSS
0.4% EPSS
path-traversal 2026-07-15
CVE-2024-28335 🟠 Łataj w tym tygodniu

Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses Ja…

9.1 CVSS
0.4% EPSS
path-traversal 2024-03-27