Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,512 CVEs tagged with CWE-221,265 Critical, 3,936 High, 3,913 Medium, 390 Low, 8 Unrated.

CVE-2026-48777

Published Jun 16, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPa…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-8442

Published Jun 16, 2026

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the w…

CVSS 8.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-49766

Published Jun 15, 2026

Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-49061

Published Jun 15, 2026

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-40779

Published Jun 15, 2026

Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40769

Published Jun 15, 2026

Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code Field <= 1.0.6 versions.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40727

Published Jun 15, 2026

Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39489

Published Jun 15, 2026

Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39468

Published Jun 15, 2026

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50877

Published Jun 15, 2026

An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50869

Published Jun 15, 2026

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45390

Published Jun 15, 2026

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects suc…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-20262

Published Jun 15, 2026

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on th…

CVSS 6.5 · Medium
evidence mentions
10
Buzz score
69.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2016-20081

Published Jun 15, 2026

WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_pat…

CVSS 8.7 · High

CVE-2016-20076

Published Jun 15, 2026

WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the de…

CVSS 8.7 · High

CVE-2026-12211

Published Jun 15, 2026

A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interf…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-12198

Published Jun 15, 2026

A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executi…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-9062

Published Jun 13, 2026

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitra…

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-11769

Published Jun 13, 2026

We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12089

Published Jun 13, 2026

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the co…

CVSS 4.9 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-11442

Published Jun 13, 2026

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installatio…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-53825

Published Jun 12, 2026

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to r…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53519

Published Jun 12, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler trea…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54394

Published Jun 12, 2026

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields s…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45775

Published Jun 12, 2026

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a pa…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 401-425 of 9,512 CVEsPage 17 of 381