Skip to main content

CWE archive

CWE-23 CVEs

Programmatic archive

460 CVEs tagged with CWE-2357 Critical, 204 High, 169 Medium, 30 Low, 0 Unrated.

CVE-2026-18192

Published Jul 29, 2026

VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-63303

Published Jul 28, 2026

A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolv…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-47078

Published Jul 27, 2026

Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 an…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2026-15802

Published Jul 22, 2026

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-58481

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its pat…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-58413

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.bac…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-51026

Published Jul 20, 2026

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-54910

Published Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-cont…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-15415

Published Jul 17, 2026

AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinic…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-62843

Published Jul 15, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's arc…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-56196

Published Jul 14, 2026

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-50663

Published Jul 14, 2026

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-14903

Published Jul 14, 2026

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55474

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path w…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59792

Published Jul 10, 2026

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50181

Published Jul 10, 2026

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` a…

CVSS 7.1 · High
evidence mentions
2
Buzz score
20.6
Public PoC observed

CVE-2026-59832

Published Jul 9, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59149

Published Jul 9, 2026

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-61343

Published Jul 9, 2026

LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credenti…

CVSS 8.6 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-8650

Published Jul 8, 2026

Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59996

Published Jul 8, 2026

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVSS 4.2 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-59995

Published Jul 8, 2026

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS 4.2 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 460 CVEsPage 1 of 19