<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Path Traversal</title>
  <link>https://cvedaily.com/pages/tags/path.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/path.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Path Traversal</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2024-47273 – An improper limitation of a pathname to a restricted directory ('Path Traversal'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47273</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47273</strong></p>
  <p>An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47263 – An improper limitation of a pathname to a restricted directory ('Path Traversal'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47263</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47263</strong></p>
  <p>An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49144 – BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49144</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49144</strong></p>
  <p>BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35718 – A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35718</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35718</strong></p>
  <p>A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43965 – Path traversal vulnerability in Gleam's dependency management allows arbitrary d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43965</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43965</strong></p>
  <p>Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content.  Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc are passed without validation to paths.build_packages_package(), which constructs a filesystem path by joining the project build directory with the attacker-contro…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32685 – Path traversal vulnerability in Gleam's handling of custom documentation pages a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32685</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32685</strong></p>
  <p>Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.  The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended project and documentation output directories. The documentation.pages[].path…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10621 – Path traversal in restore handler in Collibra Agent, allows an attacker to write...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10621</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10621</strong></p>
  <p>Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5422 – A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5422</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5422</strong></p>
  <p>A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, th…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0055 – In createSessionInternal of PackageInstallerService.java, there is a possible to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0055</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0055</strong></p>
  <p>In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49136 – Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49136</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49136</strong></p>
  <p>Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete path prefix check using os.path.startswith() without a trailing separator. Attackers can supply cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45727 – CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45727</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45727</strong></p>
  <p>CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve port can supply a crafted fingerprint value containing path traversal sequences to resolve user_dat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45279 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45279</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45279</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is used in the template directory config value, non-admin users can in some cases copy arbitrary files (depending on unix permissions) into their own Nextcloud directory via a path traversal. It is recommended that the Nextcloud Server is u…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43624 – F5-TTS through version 1.1.20 contains a path traversal vulnerability in the fin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43624</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43624</strong></p>
  <p>F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized user-supplied project names directly to os.path.join() without validating the resulting path stays within the intended base directory. Attackers can supply absolute path arguments such as /tmp/EVIL to override t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10278 – A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10278</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10278</strong></p>
  <p>A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a manipulation of the argument filePath/outputPath can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem e…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42679 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42679</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42679</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal.  This issue affects Classified Listing: from n/a through 5.3.8.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48866 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48866</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48866</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal.  This issue affects Gravity Forms: from n/a through 2.10.0.1.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10264 – A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10264</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10264</strong></p>
  <p>A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be utilized. Patch name: 6657cdceadd361e8fbe824afe9d00b4504009a5d. It is recommende…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40646 – Vertex is a management tool for PT (Private Tracker) users to manage streaming a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40646</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40646</strong></p>
  <p>Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc95f5445750d282e11 are vulnerable to path traversal. Users should upgrade to a version containing commit fbde301b97986d5913fc4bc95f5445750d282e11 to receive a patch.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48827 – Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48827</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48827</strong></p>
  <p>Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory.     Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected.     Users are a…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40548 – SOPlanning does not verify uploaded file extension. An authenticated attacker wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40548</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40548</strong></p>
  <p>SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on the server. When combined with CVE-2026-40547 (Path Traversal), the malicious file (e.g., a PHP script) can be placed in a web-accessible location and executed…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40547 – SOPlanning is vulnerable to Path Traversal in backup endpoints.  Authenticated r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40547</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40547</strong></p>
  <p>SOPlanning is vulnerable to Path Traversal in backup endpoints.  Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files previously added through the backup functionality. Critically, due to CVE-2026-40543 (Missing Authorization), any backup file can be read by any (unauthorized) user.  This issue affects SOPlanning vers…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10213 – A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10213</guid>
    <pubDate>Mon, 01 Jun 2026 03:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10213</strong></p>
  <p>A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this dis…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25421 – Open STA Manager 2.3 contains a path traversal vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25421</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25421</strong></p>
  <p>Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile and traverse directories using ../ sequences to access sensitive system files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25408 – The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25408</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25408</strong></p>
  <p>The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45668 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45668</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45668</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type: launcher) with a #docName lab…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45661 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45661</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45661</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file write to remote server filesystems,…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10108 – xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10108</guid>
    <pubDate>Fri, 29 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10108</strong></p>
  <p>xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music directory by exploiting an incomplete path prefix check. Attackers can request files from sibling directories whose names share the music_path prefix by crafting traversal sequences, bypassing…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39276 – The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39276</guid>
    <pubDate>Fri, 29 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39276</strong></p>
  <p>The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25393 – Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25393</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25393</strong></p>
  <p>Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to access sensitive configuration files and system files outside the intended directory.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44239 – FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44239</guid>
    <pubDate>Fri, 29 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44239</strong></p>
  <p>FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10075 – DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10075</guid>
    <pubDate>Fri, 29 May 2026 14:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10075</strong></p>
  <p>DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10074 – DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10074</guid>
    <pubDate>Fri, 29 May 2026 14:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10074</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10073 – DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10073</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10073</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8326 – Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) Spar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8326</guid>
    <pubDate>Fri, 29 May 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8326</strong></p>
  <p>Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.  Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker.  This issue affects SparkView: before build 1127.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9559 – A path traversal vulnerability exists in the campaign import feature of Mautic 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9559</guid>
    <pubDate>Fri, 29 May 2026 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9559</strong></p>
  <p>A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign:imports:create) can write arbitrary PHP files to sensitive system directories. An attacker can exp…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41280 – Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41280</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41280</strong></p>
  <p>Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41271 – Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41271</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41271</strong></p>
  <p>Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41268 – Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Adminis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41268</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41268</strong></p>
  <p>Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44973 – Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44973</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44973</strong></p>
  <p>Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsiste…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44885 – Portainer Community Edition is a lightweight service delivery platform for conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44885</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44885</strong></p>
  <p>Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target directory on the server. The extraction function (ExtractTarGz in api/archive/targz.go) constructed out…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10044 – Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10044</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10044</strong></p>
  <p>Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49128 – Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49128</guid>
    <pubDate>Thu, 28 May 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49128</strong></p>
  <p>Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root with a user-supplied URI as plain strings without canonicalization, allowing '..' segments to survive into the resolved path and be flattened by the kernel…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33462 – A path traversal vulnerability was identified in Kibana's dashboard management f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33462</guid>
    <pubDate>Thu, 28 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33462</strong></p>
  <p>A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through the Kibana interface, the deletion request is redirected to an unintended internal endpoint, potentially resulting in t…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32847 – DeepCode through commit c991dc2 contains a path traversal vulnerability in the S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32847</guid>
    <pubDate>Thu, 28 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32847</strong></p>
  <p>DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to trav…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49238 – An issue was discovered in Canonical Multipass before version 1.16.3. The host-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49238</guid>
    <pubDate>Thu, 28 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49238</strong></p>
  <p>An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation o…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48977 – Relative Path Traversal vulnerability in Apache Ignite REST API.

Authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48977</guid>
    <pubDate>Thu, 28 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48977</strong></p>
  <p>Relative Path Traversal vulnerability in Apache Ignite REST API.  Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 through 2.17.0.  Users are recommended to upgrade to version 2.18.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9804 – A flaw was found in KubeVirt's virt-exportserver component. An attacker with spe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9804</guid>
    <pubDate>Thu, 28 May 2026 09:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9804</strong></p>
  <p>A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's files…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6455 – The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6455</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6455</strong></p>
  <p>The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46402 – Microsoft UFO open-source framework for intelligent automation across devices an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46402</guid>
    <pubDate>Wed, 27 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46402</strong></p>
  <p>Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause UFO to create log directories and log files outside the intended logs/ directory.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8361 – A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8361</guid>
    <pubDate>Wed, 27 May 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8361</strong></p>
  <p>A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-49009 – Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49009</guid>
    <pubDate>Wed, 27 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-49009</strong></p>
  <p>Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48544 – Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48544</guid>
    <pubDate>Wed, 27 May 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48544</strong></p>
  <p>Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended module directory by exploiting an incomplete path containment check using str.startswith() without a trailing path separator. Attackers can send crafted GET requests with path traver…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-47118 – Agent Zero before version 1.15 contains a path traversal vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47118</guid>
    <pubDate>Wed, 27 May 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-47118</strong></p>
  <p>Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, which relies solely on an extension allowlist while the path containment check is explicitly disabled. Attackers can request any file with an image extension readable by the process, including files outs…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42757 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42757</guid>
    <pubDate>Wed, 27 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42757</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42756 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42756</guid>
    <pubDate>Wed, 27 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42756</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly: from n/a through <= 3.2.7.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42737 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42737</guid>
    <pubDate>Wed, 27 May 2026 11:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42737</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-47267 – Improper limitation of a pathname to a restricted directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47267</guid>
    <pubDate>Wed, 27 May 2026 09:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-47267</strong></p>
  <p>Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9312 – A server-side request forgery (SSRF) vulnerability was identified in GitHub Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9312</guid>
    <pubDate>Wed, 27 May 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9312</strong></p>
  <p>A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potent…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44788 – SharpCompress is a fully managed C# library to deal with many compression types ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44788</guid>
    <pubDate>Tue, 26 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44788</strong></p>
  <p>SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file writes by chaining with a symlink entry, giving a full write primitive on th…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-42448 – Magic Wormhole makes it possible to get arbitrary-sized files and directories fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42448</guid>
    <pubDate>Tue, 26 May 2026 18:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-42448</strong></p>
  <p>Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when a receiver who specifies "--output <dir>" where that output directory currently exists (as a directory). This vulnerability is fixed in 0.24.0.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40384 – An improper validation of the search parameter of the com_media files API endpoi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40384</guid>
    <pubDate>Tue, 26 May 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40384</strong></p>
  <p>An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9550 – A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9550</guid>
    <pubDate>Tue, 26 May 2026 15:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9550</strong></p>
  <p>A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9473 – A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9473</guid>
    <pubDate>Mon, 25 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9473</strong></p>
  <p>A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem ea…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9472 – A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af8176...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9472</guid>
    <pubDate>Mon, 25 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9472</strong></p>
  <p>A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why i…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9468 – A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9468</guid>
    <pubDate>Mon, 25 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9468</strong></p>
  <p>A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the function handleInitializeMemoryBank of the file src/index.ts. The manipulation of the argument projectPath results in path traversal. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This pro…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9467 – A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9467</guid>
    <pubDate>Mon, 25 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9467</strong></p>
  <p>A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25374 – Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25374</guid>
    <pubDate>Mon, 25 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25374</strong></p>
  <p>Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25365 – PCViewer vt1000 contains a directory traversal vulnerability that allows unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25365</guid>
    <pubDate>Mon, 25 May 2026 15:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25365</strong></p>
  <p>PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use path traversal sequences ../../../../../../../../../../../../etc/passwd to access sensitive system files outside the intended directory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7766 – Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7766</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7766</strong></p>
  <p>Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server.  The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in version 2025-04-21.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9351 – A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9351</guid>
    <pubDate>Sun, 24 May 2026 04:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9351</strong></p>
  <p>A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/file_tools.py of the component read_file Tool. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted earl…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-36227 – Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36227</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-36227</strong></p>
  <p>Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45145 – Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45145</guid>
    <pubDate>Fri, 22 May 2026 15:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45145</strong></p>
  <p>Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34911 – A malicious actor with access to the network and low privileges could exploit a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34911</guid>
    <pubDate>Fri, 22 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34911</strong></p>
  <p>A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34909 – A malicious actor with access to the network could exploit a Path Traversal vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34909</guid>
    <pubDate>Fri, 22 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34909</strong></p>
  <p>A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8134 – Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8134</guid>
    <pubDate>Thu, 21 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8134</strong></p>
  <p>Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code i…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34926 – A directory traversal vulnerability in the Apex One (on-premise) server could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34926</guid>
    <pubDate>Thu, 21 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34926</strong></p>
  <p>A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.   This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained admini…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4858 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4858</guid>
    <pubDate>Thu, 21 May 2026 09:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4858</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user  to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9129 – A path traversal vulnerability exists in the Altium Enterprise Server Viewer Sto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9129</guid>
    <pubDate>Wed, 20 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9129</strong></p>
  <p>A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a Viewer storage API request, causing the configured storage root to be discarded…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9102 – A path traversal vulnerability exists in the Altium Enterprise Server Comparison...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9102</guid>
    <pubDate>Wed, 20 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9102</strong></p>
  <p>A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape the intended temporary upload directory and write arbitrary files to any location on the server filesystem.     Because…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39352 – Frappe is a full-stack web application framework. Versions prior to 15.105.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39352</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39352</strong></p>
  <p>Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24217 – NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24217</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24217</strong></p>
  <p>NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23734 – XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23734</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23734</strong></p>
  <p>XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be exploited via resources parameter the ssx and jsx endpoints by using leading slashes.…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24209 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24209</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24209</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24208 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24208</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24208</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-36829 – An authentication bypass vulnerability exists in the embedded HTTP server of Pan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36829</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-36829</strong></p>
  <p>An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing directory traversal and bypass of authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70950 – An issue in gohttp commit 34ea51 allows attackers to execute a directory travers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70950</guid>
    <pubDate>Tue, 19 May 2026 15:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70950</strong></p>
  <p>An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46724 – The file indexer does not normalize the configured directory path. A backend use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46724</guid>
    <pubDate>Tue, 19 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46724</strong></p>
  <p>The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31379 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31379</guid>
    <pubDate>Tue, 19 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31379</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29220 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29220</guid>
    <pubDate>Tue, 19 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29220</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27891 – FacturaScripts is an open source accounting and invoicing software. Versions 202...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27891</guid>
    <pubDate>Mon, 18 May 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27891</strong></p>
  <p>FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leading to Arbitrary File Write and Remote Code Execution (RCE) by overwriting sensitive .php files outsi…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22810 – Joplin is an open source note-taking and to-do application that organises notes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22810</guid>
    <pubDate>Mon, 18 May 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22810</strong></p>
  <p>Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .o…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-24</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-47091 – Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47091</guid>
    <pubDate>Mon, 18 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-47091</strong></p>
  <p>Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a persistent cache file with insufficient permissions, creating a forensic record of accessed paths tha…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45242 – Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/sum...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45242</guid>
    <pubDate>Mon, 18 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45242</strong></p>
  <p>Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit this to write slide_*.png and slides.json files to any writable directory and subsequently delete matc…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45230 – DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45230</guid>
    <pubDate>Mon, 18 May 2026 18:17:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45230</strong></p>
  <p>DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29963 – HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper val...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29963</guid>
    <pubDate>Mon, 18 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29963</strong></p>
  <p>HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this flaw to access arbitrary files on the underlying operating system, resulting in unauthorized disclosu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29962 – HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29962</guid>
    <pubDate>Mon, 18 May 2026 18:17:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29962</strong></p>
  <p>HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arb…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41948 – Dify version 1.14.1 and prior contain a path traversal vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41948</guid>
    <pubDate>Mon, 18 May 2026 15:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41948</strong></p>
  <p>Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints s…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7302 – SGLangs multimodal generation runtime is vulnerable to an unauthenticated path t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7302</guid>
    <pubDate>Mon, 18 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7302</strong></p>
  <p>SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8802 – A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8802</guid>
    <pubDate>Mon, 18 May 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8802</strong></p>
  <p>A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as def0c27a0e252668df8d942fc31e16d1edfd7323. A patch should be applied to remediate this issue. T…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8770 – A vulnerability was identified in continuedev continue up to 1.2.22. This affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8770</guid>
    <pubDate>Mon, 18 May 2026 00:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8770</strong></p>
  <p>A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON-RPC Server. Such manipulation of the argument dirPath leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure b…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8770">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
