Skip to main content

CWE archive

CWE-23 CVEs

Programmatic archive

457 CVEs tagged with CWE-2357 Critical, 203 High, 167 Medium, 30 Low, 0 Unrated.

CVE-2026-25121

Published Feb 4, 2026

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's d…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-24909

Published Jan 27, 2026

vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-23890

Published Jan 26, 2026

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outs…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-23888

Published Jan 26, 2026

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extracti…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-1022

Published Jan 16, 2026

Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download ar…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-68472

Published Jan 12, 2026

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67366

Published Jan 7, 2026

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerabilit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15225

Published Dec 29, 2025

WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-57403

Published Dec 26, 2025

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) direct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15015

Published Dec 22, 2025

Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbi…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66626

Published Dec 9, 2025

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versions 3.7.0 through 3.7.4, contai…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-20023

Published Dec 5, 2025

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12097

Published Dec 4, 2025

There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure.  Successful exploitation requires an attacker to send a spe…

CVSS 8.7 · High

CVE-2025-13771

Published Nov 28, 2025

WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66386

Published Nov 28, 2025

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

CVSS 4.1 · Medium

CVE-2024-47856

Published Nov 24, 2025

In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quota…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-64757

Published Nov 19, 2025

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access thr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13199

Published Nov 15, 2025

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results i…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64446

Published Nov 14, 2025

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiW…

CVSS 9.8 · Critical
evidence mentions
11
Buzz score
69.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-13161

Published Nov 14, 2025

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download…

CVSS 8.7 · High

CVE-2025-64714

Published Nov 13, 2025

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion…

CVSS 5.8 · Medium

CVE-2025-58464

Published Nov 7, 2025

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents of unexpected files…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 101-125 of 457 CVEsPage 5 of 19