CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,125 vulnerabilities with CWE-22
CVE-2026-32026
MEDIUM
OpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in Sandbox
CVSS 6.5
CVE-2026-32020
LOW
OpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File Handler
CVSS 3.3
CVE-2026-32007
MEDIUM
OpenClaw < 2026.2.23 - Sandbox Bypass in apply_patch Tool via Workspace-Only Check Bypass
CVSS 6.8
CVE-2026-32749
HIGH
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CVSS 7.6
CVE-2026-32747
MEDIUM
SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets
CVSS 6.8
CVE-2026-25928
MEDIUM
OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders
CVSS 6.5
CVE-2026-30403
HIGH
wgcloud <=3.6.3 - Arbitrary File Read
CVSS 7.5
CVE-2026-22557
CRITICAL
UniFi Network Application 9.0.118-10.1.89, 10.2.97 - Path Traversal
CVSS 10.0
CVE-2026-32805
HIGH
Romeo is vulnerable to Archive Slip due to missing checks in sanitization
CVSS 7.5
CVE-2026-32731
CRITICAL
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
CVSS 9.9
CVE-2026-3479
NONE
pkgutil.get_data() does not enforce documented restrictions
CVE-2026-27523
MEDIUM
OpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf Paths
CVSS 6.1
CVE-2026-27522
MEDIUM
OpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message Actions
CVSS 6.5
CVE-2026-22171
HIGH
OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming
CVSS 8.2
CVE-2026-32981
HIGH
Ray Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure
CVSS 7.5
CVE-2026-25770
CRITICAL
Wazuh has Privilege Escalation to Root via Cluster Protocol File Write
CVSS 9.1
CVE-2026-4307
MEDIUM
frdel/agent0ai agent-zero files.py get_abs_path path traversal
CVSS 4.3
CVE-2026-4285
LOW
taoofagi easegen-admin Pdf2MdUtil.java recognizeMarkdown path traversal
CVSS 2.7
CVE-2026-21991
MEDIUM
Oracle Linux 8 - Arbitrary File Creation
CVSS 5.5
CVE-2026-29522
HIGH
ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI
CVE-2026-32262
MEDIUM
Craft CMS < 4.17.5 and 5.9.11 - AssetsController Path Traversal File Deletion
CVSS 4.3
CVE-2026-4233
MEDIUM
ThingsGateway download path traversal
CVSS 4.3
CVE-2026-4222
LOW
SSCMS download PathUtils.RemoveParentPath path traversal
CVSS 3.8
CVE-2026-3839
HIGH
Unraid < 7.2.3 - Unauthenticated Path Traversal Authentication Bypass via auth-request.php
CVSS 7.3
CVE-2026-3838
HIGH
Unraid - Authenticated Remote Code Execution via Update Request Path Traversal
CVSS 8.8
Details
Vulnerabilities
9,125
Exploit Likelihood
High