Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,512 CVEs tagged with CWE-221,265 Critical, 3,936 High, 3,913 Medium, 390 Low, 8 Unrated.

CVE-2026-53779

Published Jun 22, 2026

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by s…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-54286

Published Jun 22, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49356

Published Jun 22, 2026

Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @b…

CVSS 3.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12479

Published Jun 22, 2026

A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This v…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56448

Published Jun 22, 2026

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-42129

Published Jun 22, 2026

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10601

Published Jun 22, 2026

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configu…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12821

Published Jun 22, 2026

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-56394

Published Jun 21, 2026

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence ch…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-11911

Published Jun 20, 2026

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to,…

CVSS 7.5 · High
evidence mentions
7
Buzz score
32.3

CVE-2026-9843

Published Jun 20, 2026

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page f…

CVSS 8.1 · High
evidence mentions
8
Buzz score
33.5

CVE-2026-48129

Published Jun 19, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly u…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49342

Published Jun 19, 2026

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanu…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-49340

Published Jun 19, 2026

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authentica…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49339

Published Jun 19, 2026

gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a7df75789f410` added an ownership…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-49290

Published Jun 19, 2026

Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slo…

CVSS 7.6 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-56138

Published Jun 19, 2026

AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior t…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8713

Published Jun 19, 2026

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all version…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
33.9
Public PoC observed

CVE-2026-7547

Published Jun 19, 2026

The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insuffic…

CVSS 4.9 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-54414

Published Jun 19, 2026

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrat…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-56078

Published Jun 18, 2026

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal se…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-54017

Published Jun 18, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48716

Published Jun 18, 2026

nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path using the fileName field from an…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54223

Published Jun 18, 2026

UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s server that application has privil…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Showing 351-375 of 9,512 CVEsPage 15 of 381