CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-65886
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
CVE-2026-65889
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
CVE-2026-44943
MEDIUM
remote limited file-write as root via discovery in open-iscsi
CVE-2026-11974
HIGH
Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Download
CVSS 8.6
CVE-2026-66063
MEDIUM
goshs has a Path Traversal issue
CVSS 6.5
CVE-2026-54659
MEDIUM
Pagy I18n locale option is not validated before being used in a file path
CVE-2026-54650
HIGH
openhole-server vulnerable to path traversal via URL-decoded request path
CVSS 8.6
CVE-2026-55390
HIGH
datamodel-code-generator 0.59.0-0.62.0 - XSD Path Traversal File Read
CVSS 7.5
CVE-2026-55389
HIGH
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
CVSS 7.5
CVE-2026-15280
HIGH
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
CVSS 7.5
CVE-2026-14973
CRITICAL
IBM Aspera Desktop App 1.0.5-1.0.19 - Path Traversal
CVSS 9.3
CVE-2026-5114
MEDIUM
SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read
CVSS 4.9
CVE-2026-48374
HIGH
Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 7.8
CVE-2026-67185
HIGH
TinyWeb 0.0.8 Path Traversal via URL Path Component
CVSS 7.5
CVE-2026-54545
HIGH
@wakaru/cli arbitrary file write during bundle unpack
CVSS 7.1
CVE-2026-7521
MEDIUM
SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
CVSS 5.5
CVE-2026-16585
HIGH
Better Messages <= 2.15.19 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter
CVSS 7.2
CVE-2026-14490
HIGH
Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action
CVSS 7.5
CVE-2026-17524
HIGH
Zip-lib < 1.1.0 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.5
CVE-2026-64740
CRITICAL
Apple Ios And iPadOS - Denial of Service
CVSS 9.3
CVE-2026-64731
CRITICAL
macOS <15.7.8 and <26.6 - Sandbox Escape via Path Handling Issue
CVSS 9.8
CVE-2026-43772
HIGH
Apple macOS - Path Traversal
CVSS 8.2
CVE-2026-43749
HIGH
Apple macOS - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.8
CVE-2026-43723
HIGH
Apple Ios And iPadOS - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 7.8
CVE-2026-65921
HIGH
jfrog artifactory - Potential Path Traversal Leading to Unauthorized File Writes
CVSS 8.8
Details
Vulnerabilities
9,572
Exploit Likelihood
High