CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,570 vulnerabilities with CWE-22
CVE-2026-56673
HIGH
ComfyUI < 0.28.0 LoadImage - Unauthenticated Path Traversal
CVSS 7.5
CVE-2026-56671
HIGH
ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read
CVSS 7.5
CVE-2026-63222
HIGH
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
CVSS 7.5
CVE-2026-55495
MEDIUM
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
CVSS 4.3
CVE-2026-66755
MEDIUM
Apache Tika: Arbitrary Local File Read in ISArchiveParser
CVE-2026-12942
HIGH
Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints
CVSS 7.5
CVE-2026-62663
HIGH
Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/video/document)
CVSS 7.5
CVE-2026-52680
ANALYSIS PENDING
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
CVE-2026-6540
HIGH
Tigera Calico - L7 Policy Bypass via Unnormalized HTTP Path Matching
CVE-2026-15435
CRITICAL
IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability
CVSS 9.8
CVE-2026-14519
HIGH
IBM App Connect Enterprise 12/13 - Path Traversal Arbitrary File Read
CVSS 7.5
CVE-2026-59310
CRITICAL
Vmware Cloud Foundation < 9.1.x.x - Path Traversal
CVSS 9.8
CVE-2026-16531
MEDIUM
Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet
CVSS 5.3
CVE-2026-67247
HIGH
Asustor Inc. Adm < 5.1.3.RI81 - Path Traversal
CVE-2026-67246
MEDIUM
A path traversal vulnerability was found in the Wallpaper component of ADM
CVE-2026-67245
HIGH
Asustor Inc. Adm < 5.1.3.RI81 - Path Traversal
CVE-2026-5492
MEDIUM
DriveLock Directory Traversal Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-5491
HIGH
DriveLock Directory Traversal Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-5489
MEDIUM
DriveLock Directory Traversal Information Disclosure Vulnerability
CVSS 5.3
CVE-2026-5487
HIGH
DriveLock Directory Traversal Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-67429
CRITICAL
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
CVSS 10.0
CVE-2026-13723
MEDIUM
Develar's electron-builder allows arbitrary file overwrite
CVSS 6.5
CVE-2026-50558
MEDIUM
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
CVSS 5.9
CVE-2026-65886
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
CVE-2026-65889
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
Details
Vulnerabilities
9,570
Exploit Likelihood
High