CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,576 vulnerabilities with CWE-22
CVE-2026-11367 MEDIUM
PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
CVSS 6.5
CVE-2026-58302 HIGH
LinuxCNC < 2.9.9 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.4
CVE-2026-12243 HIGH
Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
CVSS 7.5
CVE-2026-8023 HIGH
Zephyr 4.0.0-4.4.0 HTTP Static FS - Path Traversal File Read
CVSS 7.5
CVE-2026-43732 MEDIUM
Apple Safari - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 6.5
CVE-2026-36848 HIGH
Gigamon GVOS <= 5.16.1 - Directory Traversal in H-VUE Subsystem
CVSS 7.5
CVE-2026-11720 CRITICAL
Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder
CVSS 9.1
CVE-2026-13748 MEDIUM
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
CVSS 6.3
CVE-2026-57331 CRITICAL
WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerability
CVSS 9.9
CVE-2026-55607 HIGH
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
CVSS 8.8
CVE-2026-40521 HIGH
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
CVSS 8.8
CVE-2026-57346 HIGH
WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability
CVSS 7.1
CVE-2026-57966 MEDIUM
Spice-vdagent: path traversal in file transfer via unsanitized filename
CVSS 4.4
CVE-2026-13528 HIGH
YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal
CVSS 7.3
CVE-2026-13509 MEDIUM
RAGapp Knowledge File files.py FileHandler.remove_file path traversal
CVSS 6.3
CVE-2026-13503 MEDIUM
antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
CVSS 5.3
CVE-2026-28701 CRITICAL
Daktronics Controller Firmware Path Traversal
CVSS 9.8
CVE-2026-49984 HIGH
Kestra LocalStorage - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-45807 HIGH
Kestra File Endpoints - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-54352 CRITICAL
Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
CVSS 9.6
CVE-2026-49991 HIGH
RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection
CVSS 8.6
CVE-2026-29509 MEDIUM
Patool < 4.0.5 Path Traversal via safe_extract() Function
CVSS 5.4
CVE-2026-56876 HIGH
extract-zip unvalidated symlink path traversal
CVSS 8.1
CVE-2026-54557 MEDIUM
mise HTTP backend uses raw version path for install symlink destination
CVSS 5.5
CVE-2026-55677 HIGH
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
CVSS 7.5
Details
Vulnerabilities 9,576
Exploit Likelihood High