Threats Tagged 'cwe-23'
View all threats tagged with 'cwe-23'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-23'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-41046: CWE-23 Relative path traversal in presire qSnapperCVE-2026-41046 0 A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root. Join the discussion | CVE Database V5 | 06/22/2026, 15:20:30 UTC Added: 06/22/2026, 15:39:21 UTC |
CVE-2026-49290: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in byrongamatos slopsmithCVE-2026-49290 0 Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slopsmith's archive extractors allows an attacker to write arbitrary files outside the extraction directory by supplying a crafted PSARC or sloppak archive. With the default Docker configuration (running as root) and the ability to drop a file into the plugin directory, this escalates to arbitrary remote code execution on the host. Three archive extractors concatenated archive-entry filenames directly onto the extraction root without validation: `lib/psarc.py::unpack_psarc` — PSARC TOC filenames; `lib/patcher.py::unpack_psarc` — duplicate of the above in the patcher flow; `lib/sloppak.py::_unpack_zip` — bare `ZipFile.extractall()` with no member filter. Each accepts entry names containing `..` segments, absolute paths, or backslash separators. The Python `zipfile` module's default `extractall()` is documented as not preventing traversal when callers don't supply a member-filter callback. Version 0.2.9-alpha.5 patches the issue. Until updated, do not open PSARC or sloppak archives from untrusted sources, and do not expose the Slopsmith instance to the public internet. Docker users should also pull the latest image after the next slopsmith Docker image is published. Join the discussion | CVE Database V5 | 06/19/2026, 17:31:05 UTC Added: 06/19/2026, 18:37:16 UTC |
CVE-2026-10720: CWE-23 Relative path traversal in Canonical MicrocephCVE-2026-10720 0 Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state. Join the discussion | CVE Database V5 | 06/19/2026, 04:57:48 UTC Added: 06/19/2026, 06:20:05 UTC |
CVE-2026-8100: CWE-23 Relative path traversal in Progress Chef Chef360CVE-2026-8100 0 Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standard access controls gaining additional privileges, potentially allowing access to API endpoints that are intended to be restricted to higher-permissioned roles. The impact is limited to environments where the affected request patterns can be triggered and depends on specific deployment configuration and access controls in place. Resolution The issue has been addressed through product updates that improve request validation and enforce strict path normalization before authorization checks. Customers are advised to update to the latest available version containing the fix, version 1.7.1 or later. Join the discussion | CVE Database V5 | 06/18/2026, 21:18:27 UTC Added: 06/18/2026, 22:06:01 UTC |
CVE-2026-34026: CWE-23 Relative path traversal in Wertheim GmbH Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)CVE-2026-34026 0 Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without sufficient validation, allowing an authenticated attacker with any role or permission level to traverse out of the intended document directory and download arbitrary files accessible to the application. This includes, but is not limited to, application log files containing sensitive information and application binaries. Join the discussion | CVE Database V5 | 06/15/2026, 10:04:13 UTC Added: 06/15/2026, 12:00:20 UTC |
CVE-2026-48569: CWE-20: Improper Input Validation in Microsoft Visual Studio CodeCVE-2026-48569 0 Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Join the discussion | GCVE Database | 06/09/2026, 17:05:53 UTC Added: 06/10/2026, 21:23:15 UTC |
CVE-2024-43614: CWE-23: Relative Path Traversal in Microsoft Microsoft Defender for Endpoint for LinuxCVE-2024-43614 0 Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. Join the discussion | GCVE Database | 10/08/2024, 17:36:18 UTC Added: 06/09/2026, 19:18:40 UTC |
CVE-2026-47287: CWE-23: Relative Path Traversal in Microsoft Visual Studio CodeCVE-2026-47287 0 Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. Join the discussion | CVE Database V5 | 06/09/2026, 17:04:57 UTC Added: 06/09/2026, 17:27:08 UTC |
CVE-2026-48681: CWE-23 Relative Path Traversal in OpenStack IronicCVE-2026-48681 0 OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. Join the discussion | CVE Database V5 | 06/04/2026, 00:00:00 UTC Added: 06/04/2026, 03:48:37 UTC |
CVE-2026-5422: CWE-23 Relative Path Traversal in jupyter jupyter/jupyterCVE-2026-5422 0 CVE-2026-5422 is a path traversal vulnerability in jupyter-server version 2.17.0. It arises from an improper root directory boundary check in the _get_os_path() function, which uses a startswith check without a trailing path separator. This allows sibling directories with similar prefixes to bypass the check. Additionally, the to_os_path() function does not remove '.. ' path parts, enabling traversal sequences to circumvent protections. This can lead to unauthorized read/write access to files in sibling directories, risking exposure of sensitive data in shared hosting environments. Join the discussion | CVE Database V5 | 06/02/2026, 09:11:15 UTC Added: 06/02/2026, 10:03:50 UTC |
Showing 1 to 10 of 19 results