Skip to main content

CWE archive

CWE-24 CVEs

Programmatic archive

113 CVEs tagged with CWE-245 Critical, 25 High, 71 Medium, 12 Low, 0 Unrated.

CVE-2026-66140

Published Jul 24, 2026

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46687

Published Jul 16, 2026

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44942

Published Jun 18, 2026

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill dir…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-49103

Published May 27, 2026

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-22810

Published May 18, 2026

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the imp…

CVSS 8.2 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-33431

Published Apr 20, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver p…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40318

Published Apr 16, 2026

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the u…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39813

Published Apr 14, 2026

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via speci…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2024-43035

Published Mar 5, 2026

Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voic…

CVSS 5.8 · Medium

CVE-2026-28538

Published Mar 5, 2026

Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28427

Published Mar 4, 2026

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitiz…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-21857

Published Jan 7, 2026

REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversa…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-67364

Published Jan 7, 2026

fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-21436

Published Jan 1, 2026

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape the directory set by `--destdir`. This requires the installat…

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-68430

Published Dec 19, 2025

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67845

Published Dec 19, 2025

A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61318

Published Dec 8, 2025

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perf…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-51661

Published Nov 19, 2025

A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13199

Published Nov 15, 2025

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results i…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-63298

Published Oct 30, 2025

A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with ad…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-53691

Published Oct 22, 2025

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wil…

CVSS 8.3 · High

CVE-2025-60344

Published Oct 21, 2025

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory…

CVSS 8.6 · High

CVE-2025-57618

Published Oct 14, 2025

A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the server. By leveraging this vulnerability, it is possible to…

CVSS 7.3 · High

CVE-2025-57563

Published Oct 14, 2025

A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.

CVSS 6.5 · Medium
Showing 1-25 of 113 CVEsPage 1 of 5