Total
184 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-27557 | 2026-09-16 | N/A | 7.5 HIGH | ||
| An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read. | |||||
| CVE-2026-28265 | 1 Dell | 13 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 10 more | 2026-09-11 | N/A | 4.4 MEDIUM |
| PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files. | |||||
| CVE-2026-21092 | 1 Samsung | 1 Android | 2026-09-11 | N/A | 5.3 MEDIUM |
| Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege. | |||||
| CVE-2026-85310 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. | |||||
| CVE-2026-21103 | 1 Samsung | 1 Android | 2026-09-10 | N/A | 6.1 MEDIUM |
| Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege. | |||||
| CVE-2026-20513 | 2026-09-08 | N/A | 4.4 MEDIUM | ||
| In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245. | |||||
| CVE-2026-69109 | 2026-08-28 | N/A | 7.5 HIGH | ||
| A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. | |||||
| CVE-2026-56089 | 1 Dell | 1 Objectscale | 2026-08-19 | N/A | 3.3 LOW |
| Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |||||
| CVE-2026-59909 | 1 Dell | 1 Objectscale | 2026-08-19 | N/A | 7.1 HIGH |
| Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |||||
| CVE-2026-13716 | 1 Craftycontrol | 1 Crafty Controller | 2026-08-18 | N/A | 9.1 CRITICAL |
| Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | |||||
| CVE-2025-68428 | 1 Parall | 1 Jspdf | 2026-08-18 | N/A | 7.5 HIGH |
| jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary files in the local file system the node process is running in. The file contents are included verbatim in the generated PDFs. Other affected methods are `addImage`, `html`, and `addFont`. Only the node.js builds of the library are affected, namely the `dist/jspdf.node.js` and `dist/jspdf.node.min.js` files. The vulnerability has been fixed in jsPDF@4.0.0. This version restricts file system access per default. This semver-major update does not introduce other breaking changes. Some workarounds areavailable. With recent node versions, jsPDF recommends using the `--permission` flag in production. The feature was introduced experimentally in v20.0.0 and is stable since v22.13.0/v23.5.0/v24.0.0. For older node versions, sanitize user-provided paths before passing them to jsPDF. | |||||
| CVE-2026-28157 | 2026-08-14 | N/A | 7.5 HIGH | ||
| Subscriber Path Traversal in Do Lasso <= 358 versions. | |||||
| CVE-2026-66695 | 2026-08-12 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | |||||
| CVE-2025-8088 | 3 Dtsearch, Microsoft, Rarlab | 3 Dtsearch, Windows, Winrar | 2026-08-11 | N/A | 8.8 HIGH |
| A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. | |||||
| CVE-2026-59115 | 1 Microsoft | 1 Entra Provisioning Service | 2026-08-07 | N/A | 9.9 CRITICAL |
| '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2025-59181 | 2026-07-28 | N/A | N/A | ||
| Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users. | |||||
| CVE-2026-49779 | 2026-07-28 | N/A | 6.5 MEDIUM | ||
| Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5. | |||||
| CVE-2025-60835 | 2026-07-24 | N/A | 7.8 HIGH | ||
| An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. | |||||
| CVE-2026-44933 | 2026-07-24 | N/A | 7.8 HIGH | ||
| `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges. | |||||
| CVE-2026-24315 | 2026-07-23 | N/A | 4.2 MEDIUM | ||
| SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted. | |||||
