Skip to main content

CWE archive

CWE-26 CVEs

Programmatic archive

17 CVEs tagged with CWE-263 Critical, 10 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-46747

Published Jun 9, 2026

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFil…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42196

Published May 12, 2026

django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-25575

Published Feb 4, 2026

NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in the propose_edits endpoint allo…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2022-45133

Published Aug 22, 2025

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file could allow one to traverse the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53908

Published Jul 16, 2025

RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path traversal vulnerability in the `/api/raw` endpoint. Anyone runni…

CVSS 8.3 · High

CVE-2025-25295

Published Feb 14, 2025

Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-5866

Published Jul 2, 2024

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5865

Published Jul 2, 2024

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the web pu…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28064

Published May 18, 2024

Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with disp…

CVSS 9.8 · Critical

CVE-2024-29466

Published Apr 30, 2024

Directory Traversal vulnerability in lsgwr spring boot online exam v.0.9 allows an attacker to execute arbitrary code via the FileTransUtil.java component.

CVSS 8.8 · High

CVE-2024-31551

Published Apr 26, 2024

Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20345

Published Mar 6, 2024

A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affecte…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-25466

Published Feb 16, 2024

Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50255

Published Dec 27, 2023

Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25802

Published Mar 13, 2023

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42021

Published Nov 9, 2021

A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video…

CVSS 7.5 · High
Showing 1-17 of 17 CVEsPage 1 of 1