Total
319 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-2818 | 2026-07-15 | N/A | 8.2 HIGH | ||
| A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only. | |||||
| CVE-2026-27489 | 1 Linuxfoundation | 1 Onnx | 2026-07-15 | N/A | 7.5 HIGH |
| Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0. | |||||
| CVE-2026-59792 | 1 Jetbrains | 1 Intellij Idea | 2026-07-14 | N/A | 9.6 CRITICAL |
| In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | |||||
| CVE-2026-50181 | 2026-07-14 | N/A | 7.1 HIGH | ||
| Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operations. However, the tools only change the process working directory to `curr_dir` and then operate on the user-supplied `file_path` without resolving and enforcing that the final path remains inside `curr_dir`. As a result, a tool caller can supply path traversal sequences such as `../secret.txt` to read files outside the configured current directory, or `../written_by_tool.txt` to write files outside that directory. This can impact applications that expose Langroid file tools to an LLM agent, user-controlled tool call, or delegated coding/documentation agent while relying on `curr_dir` to restrict file access to a project/workspace directory. Version 0.64.0 patches the issue. | |||||
| CVE-2026-31927 | 1 Anviz | 2 Cx7, Cx7 Firmware | 2026-07-10 | N/A | 4.9 MEDIUM |
| Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes. | |||||
| CVE-2026-55474 | 1 Snipeitapp | 1 Snipe-it | 2026-07-10 | N/A | 6.5 MEDIUM |
| Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0. | |||||
| CVE-2026-59149 | 2026-07-10 | N/A | 6.5 MEDIUM | ||
| Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBaseDir). That prefix test has no path-separator boundary, so a ../-escaped path whose absolute form string-prefixes the base directory passes, allowing an unauthenticated client to read files from sibling paths outside the served directory through HTTP sendFile, WebSocket, or callbacks. This issue is fixed in version 9.7.0. | |||||
| CVE-2026-59832 | 2026-07-10 | N/A | 7.7 HIGH | ||
| SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as /snippets/%2e%2e/%2e%2e/conf/conf.json to read workspace secrets and the document database. This issue is fixed in versions 3.7.1. | |||||
| CVE-2026-61343 | 2026-07-09 | N/A | 7.2 HIGH | ||
| LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0. | |||||
| CVE-2026-8650 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 4.5 MEDIUM |
| Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-59995 | 1 Openbsd | 1 Openssh | 2026-07-09 | N/A | 4.2 MEDIUM |
| sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. | |||||
| CVE-2026-59996 | 1 Openbsd | 1 Openssh | 2026-07-09 | N/A | 4.2 MEDIUM |
| scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. | |||||
| CVE-2025-53829 | 2026-07-08 | N/A | 8.0 HIGH | ||
| ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch. | |||||
| CVE-2026-58522 | 2 Google, Microsoft | 2 Android, Edge Chromium | 2026-07-07 | N/A | 6.8 MEDIUM |
| Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-44941 | 1 Opensuse | 1 Libzypp | 2026-07-07 | N/A | 8.4 HIGH |
| A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root. | |||||
| CVE-2026-57871 | 2026-07-07 | N/A | N/A | ||
| Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3. | |||||
| CVE-2026-57988 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 7.1 HIGH |
| Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2025-66737 | 1 Yealink | 2 Sip-t21\(p\)e2, Sip-t21\(p\)e2 Firmware | 2026-07-05 | N/A | 4.3 MEDIUM |
| Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component. | |||||
| CVE-2025-51052 | 1 Vedo Suite Project | 1 Vedo Suite | 2026-07-05 | N/A | 6.5 MEDIUM |
| A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'. | |||||
| CVE-2026-8387 | 2026-07-02 | N/A | 2.4 LOW | ||
| A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()` method in `StorageManager._extract_to_cache()`. This issue arises due to the lack of path traversal validation, enabling an attacker to write arbitrary files to the filesystem. Attack vectors include dataset downloads, artifact downloads, model downloads, and offline session imports. The vulnerability can lead to remote code execution through methods such as cron job injection, SSH key overwrite, or web shell deployment. The issue is resolved in version 2.1.6. | |||||
