CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,576 vulnerabilities with CWE-22
CVE-2026-11367
MEDIUM
PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
CVSS 6.5
CVE-2026-58302
HIGH
LinuxCNC < 2.9.9 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.4
CVE-2026-12243
HIGH
Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
CVSS 7.5
CVE-2026-8023
HIGH
Zephyr 4.0.0-4.4.0 HTTP Static FS - Path Traversal File Read
CVSS 7.5
CVE-2026-43732
MEDIUM
Apple Safari - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 6.5
CVE-2026-36848
HIGH
Gigamon GVOS <= 5.16.1 - Directory Traversal in H-VUE Subsystem
CVSS 7.5
CVE-2026-11720
CRITICAL
Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder
CVSS 9.1
CVE-2026-13748
MEDIUM
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
CVSS 6.3
CVE-2026-57331
CRITICAL
WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerability
CVSS 9.9
CVE-2026-55607
HIGH
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
CVSS 8.8
CVE-2026-40521
HIGH
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
CVSS 8.8
CVE-2026-57346
HIGH
WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability
CVSS 7.1
CVE-2026-57966
MEDIUM
Spice-vdagent: path traversal in file transfer via unsanitized filename
CVSS 4.4
CVE-2026-13528
HIGH
YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal
CVSS 7.3
CVE-2026-13509
MEDIUM
RAGapp Knowledge File files.py FileHandler.remove_file path traversal
CVSS 6.3
CVE-2026-13503
MEDIUM
antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
CVSS 5.3
CVE-2026-28701
CRITICAL
Daktronics Controller Firmware Path Traversal
CVSS 9.8
CVE-2026-49984
HIGH
Kestra LocalStorage - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-45807
HIGH
Kestra File Endpoints - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-54352
CRITICAL
Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
CVSS 9.6
CVE-2026-49991
HIGH
RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection
CVSS 8.6
CVE-2026-29509
MEDIUM
Patool < 4.0.5 Path Traversal via safe_extract() Function
CVSS 5.4
CVE-2026-56876
HIGH
extract-zip unvalidated symlink path traversal
CVSS 8.1
CVE-2026-54557
MEDIUM
mise HTTP backend uses raw version path for install symlink destination
CVSS 5.5
CVE-2026-55677
HIGH
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
CVSS 7.5
Details
Vulnerabilities
9,576
Exploit Likelihood
High