Export limit exceeded: 10827 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10827 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82877 | 2 Ilias, Ilias-elearning E.v. | 2 Ilias, Ilias | 2026-09-30 | 6.5 Medium |
| ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords. | ||||
| CVE-2026-102457 | 1 Digiwin | 1 Easyflow .net | 2026-09-30 | 6.5 Medium |
| EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files. | ||||
| CVE-2026-75098 | 2026-09-30 | 7.5 High | ||
| The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors. | ||||
| CVE-2026-19743 | 1 Teamviewer | 2 Full Client, Host | 2026-09-30 | 7.8 High |
| Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation. | ||||
| CVE-2026-102252 | 1 Google | 1 Osv-scalibr | 2026-09-30 | N/A |
| A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories. | ||||
| CVE-2026-100682 | 1 Budibase | 1 Server | 2026-09-30 | 8.8 High |
| Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution. | ||||
| CVE-2026-97242 | 2026-09-30 | 6.8 Medium | ||
| Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions. | ||||
| CVE-2026-96824 | 2026-09-30 | 6.8 Medium | ||
| Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. | ||||
| CVE-2026-94123 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions. | ||||
| CVE-2026-15815 | 1 Grafana | 2 Grafana, Grafana Enterprise | 2026-09-30 | 8.8 High |
| Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS. | ||||
| CVE-2026-100536 | 1 Openclaw | 1 Openclaw | 2026-09-30 | 6.5 Medium |
| OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to read and send known host files that would otherwise be rejected. | ||||
| CVE-2026-100520 | 1 Crivion | 1 Laranode | 2026-09-30 | 8.8 High |
| Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants. | ||||
| CVE-2026-48482 | 1 Glpi-project | 1 Glpi | 2026-09-30 | N/A |
| GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8. | ||||
| CVE-2026-102242 | 1 Google | 1 Mcp Toolbox For Databases | 2026-09-29 | N/A |
| Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories. | ||||
| CVE-2024-58386 | 1 Zoneminder | 1 Zoneminder | 2026-09-29 | 6.5 Medium |
| ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials. | ||||
| CVE-2026-77257 | 2 Mcp-atlassian, Sooperset | 2 Mcp Atlassian, Mcp-atlassian | 2026-09-29 | 6.5 Medium |
| MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restricting it to the workspace. A remote MCP caller with tool access can cause the server to read sensitive local files and upload them as Atlassian attachments. The advisory traces the vulnerable input and processing flow through streamable-http, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. | ||||
| CVE-2026-77262 | 2 Mcp-atlassian, Sooperset | 2 Mcp Atlassian, Mcp-atlassian | 2026-09-29 | 8.6 High |
| MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for the earlier download vulnerability. A caller can traverse outside the workspace and upload arbitrary server-readable files to Confluence. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. | ||||
| CVE-2026-96651 | 1 Plex | 1 Media Server | 2026-09-29 | 6.5 Medium |
| Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue. | ||||
| CVE-2026-100533 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 5.3 Medium |
| OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace boundary. | ||||
| CVE-2026-100372 | 2 Clip-bucket, Macwarrior | 2 Clipbucket, Clipbucket-v5 | 2026-09-29 | 7.2 High |
| ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user. | ||||