CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,576 vulnerabilities with CWE-22
CVE-2026-59194
HIGH
pnpm: patch-remove could delete project-selected files outside the patches directory
CVSS 7.1
CVE-2026-59152
MEDIUM
Arbitrary server-side file read in LangSmith SDK TracingMiddleware
CVSS 5.0
CVE-2026-58203
MEDIUM
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
CVSS 5.3
CVE-2026-7185
MEDIUM
T-Systems Archivo - Unauthorized Access to Files in T-Systems Products
CVE-2026-49297
HIGH
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
CVSS 8.1
CVE-2026-14783
MEDIUM
NousResearch hermes-agent skills_tool.py skill_view path traversal
CVSS 4.3
CVE-2026-59510
HIGH
Authenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File Read
CVE-2026-14636
MEDIUM
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal
CVSS 5.4
CVE-2026-14635
HIGH
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
CVSS 7.3
CVE-2026-14628
MEDIUM
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
CVSS 5.3
CVE-2026-28705
MEDIUM
Gitea repository dumps write release assets using unsafe path names
CVSS 5.3
CVE-2026-41124
LOW
Dell PowerProtect Data Domain - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 2.3
CVE-2026-47896
HIGH
Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server
CVSS 7.5
CVE-2026-47897
HIGH
Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator client
CVSS 7.5
CVE-2026-9725
CRITICAL
Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
CVSS 9.1
CVE-2026-14352
HIGH
AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter
CVSS 7.5
CVE-2026-14327
HIGH
AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter
CVSS 7.5
CVE-2026-13054
HIGH
WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
CVSS 7.2
CVE-2026-58460
HIGH
react-native-receive-sharing-intent Path Traversal via _display_name
CVSS 7.7
CVE-2026-52830
CRITICAL
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVSS 9.4
CVE-2026-58467
HIGH
Cockpit CMS < 364 - Path Traversal Local File Inclusion via index.php
CVSS 7.5
CVE-2026-7311
HIGH
TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta
CVSS 8.1
CVE-2026-55117
HIGH
Ubiquiti INC UniFi Access Application < 4.2.29 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.6
CVE-2026-55111
HIGH
Ubiquiti INC UniFi Protect Floodlight < 1.13.6 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.5
CVE-2026-54406
HIGH
Ubiquiti INC UniFi Network Application < 10.4.57 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.7
Details
Vulnerabilities
9,576
Exploit Likelihood
High