Filtered by CWE-35
Total 185 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-85310 2 Adrian Tobey, Wordpress 2 Groundhogg, Wordpress 2026-09-11 6.5 Medium
import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.
CVE-2026-21103 2 Samsung, Samsung Mobile 2 Android, Samsung Mobile Devices 2026-09-11 6.1 Medium
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
CVE-2026-21092 1 Samsung Mobile 1 Samsung Mobile Devices 2026-09-11 N/A
Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
CVE-2026-20513 1 Mediatek, Inc. 1 Mediatek Chipset 2026-09-07 4.4 Medium
In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.
CVE-2026-56089 1 Dell 1 Objectscale 2026-08-19 3.3 Low
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2026-59909 1 Dell 1 Objectscale 2026-08-19 7.1 High
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
CVE-2026-13716 2 Arcadia Technology, Craftycontrol 2 Crafty Controller, Crafty Controller 2026-08-18 9.1 Critical
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
CVE-2026-28157 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.5 High
Subscriber Path Traversal in Do Lasso <= 358 versions.
CVE-2026-69109 1 Siemens 1 Siemens License Server (sls) 2026-08-13 7.5 High
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.
CVE-2026-59115 1 Microsoft 1 Entra Provisioning Service 2026-08-07 9.9 Critical
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVE-2026-66695 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-06 6.5 Medium
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2025-60835 1 Izarc 1 Unrar 2026-08-01 7.8 High
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2026-49779 2 Addify, Wordpress 2 Tax Exempt For Woocommerce, Wordpress 2026-07-28 6.5 Medium
Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.
CVE-2025-59181 1 Ericsson 1 Packet Core Controller 2026-07-27 N/A
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
CVE-2024-54216 1 Reputeinfosystems 1 Arforms 2026-07-07 7.7 High
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2.
CVE-2024-12088 8 Almalinux, Archlinux, Gentoo and 5 more 21 Almalinux, Arch Linux, Linux and 18 more 2026-06-29 6.5 Medium
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
CVE-2024-12087 8 Almalinux, Archlinux, Gentoo and 5 more 26 Almalinux, Arch Linux, Linux and 23 more 2026-06-29 6.5 Medium
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
CVE-2026-52707 2 Mikado-themes, Wordpress 2 Kastell, Wordpress 2026-06-26 8.1 High
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
CVE-2026-52703 2 Ninjateam, Wordpress 2 Fastdup, Wordpress 2026-06-26 9.6 Critical
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-49112 2 Tammersoft, Wordpress 2 Shared Files, Wordpress 2026-06-16 7.5 High
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.