Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,559 CVEs tagged with CWE-221,273 Critical, 3,961 High, 3,927 Medium, 392 Low, 6 Unrated.

CVE-2026-59310

Published Jul 30, 2026

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
25.4

CVE-2026-16531

Published Jul 30, 2026

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-67247

Published Jul 30, 2026

A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before be…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-67246

Published Jul 30, 2026

A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated bef…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-67245

Published Jul 30, 2026

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated befor…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-5492

Published Jul 29, 2026

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Drive…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-5491

Published Jul 29, 2026

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Drive…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-5489

Published Jul 29, 2026

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Drive…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-5487

Published Jul 29, 2026

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Drive…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-67429

Published Jul 29, 2026

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-13723

Published Jul 29, 2026

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-50558

Published Jul 29, 2026

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-65886

Published Jul 29, 2026

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-65889

Published Jul 29, 2026

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-44943

Published Jul 29, 2026

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-11974

Published Jul 29, 2026

The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unau…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66063

Published Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-54659

Published Jul 28, 2026

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-54650

Published Jul 28, 2026

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55390

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55389

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. P…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-15280

Published Jul 28, 2026

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mecha…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14973

Published Jul 28, 2026

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-5114

Published Jul 28, 2026

The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-48374

Published Jul 28, 2026

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker co…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 9,559 CVEsPage 1 of 383