CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
461 vulnerabilities with CWE-23
CVE-2026-59995
MEDIUM
Openbsd OpenSSH < 10.4 - Relative Path Traversal
CVSS 4.2
CVE-2026-14476
HIGH
Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass
CVSS 8.0
CVE-2026-57871
HIGH
MicroRealEstate < 1.0.0-alpha3 - Relative Path Traversal
CVE-2026-58522
MEDIUM
Microsoft Edge for Android Information Disclosure Vulnerability
CVSS 6.8
CVE-2026-57988
HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 7.1
CVE-2026-44941
HIGH
libzypp path traversal via "keyhint" in repomd.xml
CVSS 8.4
CVE-2026-8387
LOW
Relative Path Traversal in allegroai/clearml
CVSS 2.4
CVE-2026-44948
MEDIUM
Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
CVE-2026-8023
HIGH
Zephyr 4.0.0-4.4.0 HTTP Static FS - Path Traversal File Read
CVSS 7.5
CVE-2026-25707
HIGH
Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
CVSS 8.8
CVE-2026-50016
HIGH
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVSS 8.8
CVE-2026-45188
LOW
Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling
CVE-2026-54066
HIGH
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
CVSS 7.5
CVE-2026-52813
CRITICAL
Gogs: Path Traversal in organization name results in RCE through Git hooks
CVSS 10.0
CVE-2026-41046
HIGH
path traversal via `config` parameter in qSnapper
CVSS 7.3
CVE-2026-49290
HIGH
Slopsmith < 0.2.9-alpha.5 - Path Traversal Arbitrary File Write
CVE-2026-10720
MEDIUM
MicroCeph squid/tentacle remote-import API - Path Traversal
CVE-2026-8100
HIGH
Progress Chef Chef360 < 1.7.1 - Relative Path Traversal
CVE-2026-34026
HIGH
Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files
CVE-2026-48569
HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 7.1
CVE-2026-47287
MEDIUM
Visual Studio Code Tampering Vulnerability
CVSS 6.5
CVE-2026-48681
MEDIUM
Openstack Ironic - Relative Path Traversal
CVSS 5.9
CVE-2026-5422
HIGH
Path Traversal in jupyter/jupyter
CVSS 8.1
CVE-2026-10074
MEDIUM
Interinfo|DreamMaker - Arbitrary File Read
CVSS 4.9
CVE-2026-10073
HIGH
Interinfo|DreamMaker - Arbitrary File Read
CVSS 7.5
Details
Vulnerabilities
461