CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
417 vulnerabilities with CWE-23
CVE-2026-34026
HIGH
Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files
CVE-2026-48569
HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 7.1
CVE-2026-47287
MEDIUM
Visual Studio Code Tampering Vulnerability
CVSS 6.5
CVE-2026-48681
MEDIUM
Openstack Ironic - Relative Path Traversal
CVSS 5.9
CVE-2026-5422
HIGH
Path Traversal in jupyter/jupyter
CVSS 8.1
CVE-2026-10074
MEDIUM
Interinfo|DreamMaker - Arbitrary File Read
CVSS 4.9
CVE-2026-10073
HIGH
Interinfo|DreamMaker - Arbitrary File Read
CVSS 7.5
CVE-2026-8326
CRITICAL
Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCE
CVE-2026-8361
HIGH
Gladinet Triofox Path Traversal in WOSDefaultHttpModule.dll
CVSS 7.5
CVE-2026-48126
HIGH
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
CVSS 8.2
CVE-2026-8134
HIGH
Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
CVSS 7.2
CVE-2026-34926
MEDIUM
KEV
TrendAI Apex One 2019-14.0.0.17079 - Path Traversal & Arbitrary Code Deployment
CVSS 6.7
CVE-2026-23734
CRITICAL
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
CVE-2026-8073
HIGH
Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP
CVSS 7.5
CVE-2026-41948
CRITICAL
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
CVSS 9.4
CVE-2026-41612
MEDIUM
Visual Studio Code Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-41551
CRITICAL
Siemens ROS# < V2.2.2 - Path Traversal via Unsanitized User Input
CVSS 9.1
CVE-2026-8209
MEDIUM
Gibbon < 30.0.01 - Authenticated Denial of Service via Path Traversal
CVE-2026-29201
HIGH
cPanel 11.86.0-11.136.0 - Unauthenticated Arbitrary File Read via feature::LOADFEATUREFILE
CVSS 8.6
CVE-2026-43533
HIGH
OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags
CVSS 8.6
CVE-2026-43616
HIGH
Detect-It-Easy < 3.21 - Path Traversal Arbitrary File Write
CVSS 7.1
CVE-2026-42085
MEDIUM
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
CVSS 4.3
CVE-2026-22070
HIGH
ColorOS Assistant Path Traversal Vulnerability
CVSS 7.1
CVE-2026-7404
HIGH
getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal
CVSS 7.3
CVE-2026-33733
HIGH
EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete
CVSS 7.2
Details
Vulnerabilities
417