CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-59732
MEDIUM
rclone archive extract allows S3 destination prefix escape via crafted archive paths
CVSS 5.0
CVE-2026-54684
HIGH
jadx 1.5.2-1.5.5 - Code Execution via XAPK Absolute Path Traversal
CVSS 7.0
CVE-2026-53486
CRITICAL
decompress: Archive extraction can create files and links outside the target directory
CVSS 9.1
CVE-2026-48338
MEDIUM
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 6.8
CVE-2026-48319
CRITICAL
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 9.1
CVE-2026-48318
CRITICAL
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 9.9
CVE-2026-15749
MEDIUM
mastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversal
CVSS 5.3
CVE-2026-48350
HIGH
Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 8.6
CVE-2026-48310
HIGH
Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 8.6
CVE-2026-47429
CRITICAL
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
CVSS 9.8
CVE-2026-45496
MEDIUM
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 5.5
CVE-2026-15700
MEDIUM
DedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal
CVSS 4.7
CVE-2026-9108
MEDIUM
Rockwell Studio 5000 Logix Designer - ACD Project Path Traversal
CVE-2026-59839
MEDIUM
Fortinet FortiProxy - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 5.5
CVE-2026-15392
HIGH
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
CVSS 7.7
CVE-2026-11944
MEDIUM
openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download
CVSS 6.5
CVE-2026-11917
HIGH
Rockwell Automation FactoryTalk ThinManager - Path Traversal
CVE-2026-60114
HIGH
Sustainable Irrigation Platform 5.2.16 Path Traversal via JSON Backup Restore
CVSS 7.5
CVE-2026-15265
CRITICAL
Tenable Agent Path Traversal Leading to Remote Code Execution
CVSS 9.1
CVE-2026-49488
MEDIUM
Apache OpenMeetings: Arbitrary File Read
CVSS 6.5
CVE-2026-57898
CRITICAL
Eclipse BaSyx - Java Server SDK < 2.0.0-milestone-13 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 9.0
CVE-2026-12482
LOW
Path Traversal via Symlink Name Validation Bypass in keras-team/keras
CVSS 3.1
CVE-2026-15626
MEDIUM
nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal
CVSS 6.3
CVE-2026-57856
HIGH
Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API
CVSS 8.8
CVE-2026-49970
HIGH
Laravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()
CVSS 8.8
Details
Vulnerabilities
9,572
Exploit Likelihood
High