Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,481 CVEs tagged with CWE-221,258 Critical, 3,928 High, 3,900 Medium, 389 Low, 6 Unrated.

CVE-2026-49984

Published Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45807

Published Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from the client and pass it through…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54352

Published Jun 26, 2026

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49991

Published Jun 26, 2026

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal v…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-29509

Published Jun 26, 2026

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_with…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-56876

Published Jun 26, 2026

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/pa…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-54557

Published Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version strin…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55677

Published Jun 26, 2026

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (p…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57321

Published Jun 26, 2026

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-56066

Published Jun 26, 2026

Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-13426

Published Jun 26, 2026

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attac…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-64152

Published Jun 26, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0…

CVSS 9.1 · Critical

CVE-2025-55017

Published Jun 26, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0…

CVSS 9.1 · Critical

CVE-2026-57872

Published Jun 26, 2026

An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40084

Published Jun 25, 2026

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing a…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-56445

Published Jun 25, 2026

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arb…

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-55667

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54917

Published Jun 25, 2026

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway constru…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-54250

Published Jun 25, 2026

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54094

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTT…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54093

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, filebrowser builds the do…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53925

Published Jun 25, 2026

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe)…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50548

Published Jun 25, 2026

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the comman…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-55700

Published Jun 25, 2026

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest co…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 251-275 of 9,481 CVEsPage 11 of 380