CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,116 vulnerabilities with CWE-22
CVE-2026-6903
HIGH
Path Traversal Vulnerability in LabOne User Interface
CVSS 7.5
CVE-2026-41211
CRITICAL
`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`
CVSS 10.0
CVE-2026-41180
HIGH
PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart
CVSS 7.5
CVE-2026-4917
MEDIUM
IBM Guardium Data Protection is affected by multiple vulnerabilities
CVSS 4.9
CVE-2026-40062
HIGH
Ziostation2 <= 2.9.8.7 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2026-33656
CRITICAL
EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user
CVSS 9.1
CVE-2026-34414
HIGH
Xerte Online Toolkits Path Traversal via connector.php
CVSS 7.1
CVE-2026-35363
MEDIUM
uutils coreutils rm Safeguard Bypass via Improper Path Normalization
CVSS 5.6
CVE-2026-35338
HIGH
uutils coreutils chmod Path Traversal Bypass of --preserve-root
CVSS 7.3
CVE-2026-32885
MEDIUM
DDEV has ZipSlip path traversal in tar and zip archive extraction
CVSS 6.5
CVE-2026-6855
HIGH
InstructLab - Path Traversal Arbitrary File Write
CVSS 7.1
CVE-2026-4280
MEDIUM
Breaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/Read
CVSS 6.5
CVE-2026-41062
MEDIUM
AVideo <=29.0 ReceiveImage downloadURL - Path Traversal
CVSS 6.5
CVE-2026-41058
HIGH
AVideo <=29.0 CloneSite deleteDump - Path Traversal
CVSS 8.1
CVE-2026-6832
HIGH
Nesquena Hermes WebUI Arbitrary File Deletion via Unvalidated session_id
CVSS 8.1
CVE-2026-6829
MEDIUM
nesquena hermes-webui Arbitrary Workspace Directory Access
CVSS 6.3
CVE-2026-40923
MEDIUM
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
CVSS 5.4
CVE-2026-40909
HIGH
WWBN AVideo <= 29.0 - Path Traversal Remote Code Execution
CVSS 8.7
CVE-2026-40876
HIGH
SFTP root escape via prefix-based path validation in goshs
CVSS 8.8
CVE-2026-41193
CRITICAL
FreeScout < 1.8.215 - Zip Slip Remote Code Execution
CVSS 9.1
CVE-2026-40611
HIGH
Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
CVSS 8.8
CVE-2026-40576
CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in excel-mcp-server
CVSS 9.4
CVE-2026-40050
CRITICAL
CrowdStrike LogScale Unauthenticated Path Traversal
CVSS 9.8
CVE-2026-32147
MEDIUM
SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT
CVSS 4.3
CVE-2026-39973
HIGH
Apktool: Path Traversal to Arbitrary File Write
CVSS 7.1
Details
Vulnerabilities
9,116
Exploit Likelihood
High