Skip to main content

CWE archive

CWE-29 CVEs

Programmatic archive

63 CVEs tagged with CWE-2920 Critical, 36 High, 4 Medium, 3 Low, 0 Unrated.

CVE-2026-10732

Published Jun 5, 2026

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same…

CVSS 5.6 · Medium
evidence mentions
6
Buzz score
35.5

CVE-2026-24217

Published May 20, 2026

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-5627

Published Apr 7, 2026

A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper h…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-15036

Published Mar 30, 2026

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vu…

CVSS 10.0 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-30828

Published Mar 7, 2026

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been pa…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-66608

Published Feb 9, 2026

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted r…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2356

Published Feb 2, 2026

A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the…

CVSS 9.6 · Critical

CVE-2025-12790

Published Nov 6, 2025

A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

CVSS 7.4 · High
evidence mentions
3
Buzz score
25.4

CVE-2025-58291

Published Oct 11, 2025

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-50185

Published Jul 26, 2025

DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with…

CVSS 7.0 · High

CVE-2025-50184

Published Jul 26, 2025

DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restr…

CVSS 7.1 · High

CVE-2025-6209

Published Jul 7, 2025

A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `generic_utils.py`. This vulner…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8982

Published Mar 20, 2025

A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose in…

CVSS 6.2 · Medium

CVE-2024-8859

Published Mar 20, 2025

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8537

Published Mar 20, 2025

A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8248

Published Mar 20, 2025

A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7957

Published Mar 20, 2025

An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest version. The vulnerability arises from the load_credentials meth…

CVSS 9.1 · Critical

CVE-2024-12389

Published Mar 20, 2025

A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11170

Published Mar 20, 2025

A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10648

Published Mar 20, 2025

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13059

Published Feb 10, 2025

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerab…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51534

Published Feb 1, 2025

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnera…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21542

Published Dec 10, 2024

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extrac…

CVSS 6.6 · Medium

CVE-2024-7962

Published Oct 29, 2024

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7774

Published Oct 29, 2024

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the file…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 63 CVEsPage 1 of 3