Skip to main content

CWE archive

CWE-36 CVEs

Programmatic archive

131 CVEs tagged with CWE-3615 Critical, 62 High, 50 Medium, 4 Low, 0 Unrated.

CVE-2026-13189

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57211

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded b…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-15302

Published Jul 10, 2026

The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for un…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-49290

Published Jun 19, 2026

Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slo…

CVSS 7.6 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-53698

Published Jun 10, 2026

Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-10075

Published May 29, 2026

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute P…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-10044

Published May 28, 2026

Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthent…

CVSS 8.2 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-32997

Published May 28, 2026

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-4782

Published May 13, 2026

The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'cust…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-42315

Published May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the dat…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6418

Published May 5, 2026

An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44029

Published May 5, 2026

An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The f…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-7217

Published Apr 28, 2026

A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-35465

Published Apr 18, 2026

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compr…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-34515

Published Apr 1, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLM…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-4373

Published Mar 21, 2026

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::s…

CVSS 7.5 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-0846

Published Mar 9, 2026

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function d…

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-2753

Published Mar 6, 2026

An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-28414

Published Feb 27, 2026

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path tr…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27117

Published Feb 24, 2026

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulnerability ("Zip Slip") exists i…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-1330

Published Jan 22, 2026

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbi…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-1020

Published Jan 16, 2026

Police Statistics Database System developed by Gotac has a Absolute Path Traversal vulnerability, allowing unauthenticated remote attackers to enumerate the system file directory.

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 131 CVEsPage 1 of 6