Export limit exceeded: 10920 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10920 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105816 | 1 Hashicorp | 2 Vault, Vault Enterprise | 2026-10-08 | 8 High |
| Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. | ||||
| CVE-2021-3199 | 1 Onlyoffice | 1 Document Server | 2026-10-08 | 9.8 Critical |
| Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter. | ||||
| CVE-2026-105820 | 1 Hashicorp | 1 Vault Enterprise | 2026-10-08 | 5.4 Medium |
| Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, including the root namespace. This vulnerability (CVE-2026-105820) is fixed in Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23. Vault Community Edition does not support namespaces, and is not affected. | ||||
| CVE-2022-37906 | 1 Arubanetworks | 2 Arubaos, Sd-wan | 2026-10-08 | 6.5 Medium |
| An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system. | ||||
| CVE-2026-102783 | 1 Balbooa.com | 1 Gridbox Extension For Joomla | 2026-10-08 | N/A |
| Joomla Extension - balbooa.com - Path Traversal in image preview Gridbox < 2.20.4.0 - Gridbox contains the same prefix-only containment logic in its site UploaderHelper . The showImage action resolves a request-controlled path, calls that helper, and then returns the image. If image decoding is unavailable or fails, the action streams the file directly. An existing image in a sibling directory such as images-backup can therefore satisfy the current containment test even though it is outside the configured images root. The route restricts the file extension to Gridbox image types, which materially limits the read primitive. The default media root is images ; the effective site setting was not independently verified. No prefix-matching sibling directory was found alongside the site’s images directory. The finding is rated Low rather than presented as arbitrary file disclosure. | ||||
| CVE-2026-75887 | 1 Redhat | 2 Openshift, Openshift Container Platform | 2026-10-08 | 7.5 High |
| A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends. | ||||
| CVE-2026-91801 | 3 Foxit, Foxitsoftware, Microsoft | 5 Pdf Editor, Pdf Reader, Foxit Pdf Editor and 2 more | 2026-10-08 | 7.8 High |
| A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution. | ||||
| CVE-2026-102116 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 7.2 High |
| -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account. | ||||
| CVE-2026-102097 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway. | ||||
| CVE-2026-102089 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system. | ||||
| CVE-2026-97671 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-10-08 | 6.5 Medium |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability. | ||||
| CVE-2026-96419 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution | ||||
| CVE-2026-103870 | 1 Redhat | 2 Rhui, Satellite | 2026-10-07 | 5 Medium |
| A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service. | ||||
| CVE-2026-91012 | 1 Apache | 1 Karaf | 2026-10-07 | 9.8 Critical |
| org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays inside ${karaf.etc}: * if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to; * otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias. Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container. ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all. | ||||
| CVE-2026-51852 | 2026-10-07 | 7.5 High | ||
| agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. | ||||
| CVE-2026-51862 | 1 Eosphoros-ai | 1 Db-gpt | 2026-10-07 | 9.1 Critical |
| DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary. | ||||
| CVE-2026-105744 | 2 Docling, Docling-project | 2 Docling, Docling | 2026-10-07 | 7.5 High |
| Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/latex/engines/tectonic.py to compile an untrusted TikZ body and document preamble without restricting TeX file primitives including \openin and \openout. Crafted input can read files available to the converter and create or overwrite writable files, and enabling the tikz_engine_allow_shell_escape option additionally permits shell commands through TeX. The default configuration, which does not enable Tectonic rendering, is not affected. This vulnerability is fixed in 2.132.0. | ||||
| CVE-2026-79809 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 7.3 High |
| An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role. | ||||
| CVE-2026-79805 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 9.8 Critical |
| An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system. | ||||
| CVE-2026-79800 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 8.8 High |
| An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system. | ||||