Threats Tagged 'cwe-29'
View all threats tagged with 'cwe-29'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-29'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-66152 is a path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component. This flaw allows an attacker to write arbitrary files with root privileges by exploiting improper handling of file paths. The vulnerability affects versions 10.3.5 and earlier. It has a high severity with a CVSS score of 8.8, indicating significant potential impact on confidentiality, integrity, and availability. Join the discussion | GCVE Database | 08/25/2026, 19:58:47 UTC Added: 08/27/2026, 15:13:02 UTC |
CVE-2026-66152 is a path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component. This flaw allows an attacker to write arbitrary files with root privileges by exploiting improper handling of file paths. The vulnerability has a high severity score of 8.8 and impacts confidentiality, integrity, and availability. No affected versions or patch information are provided in the available data. Join the discussion | CVE Database V5 | 08/25/2026, 19:58:47 UTC Added: 08/25/2026, 20:07:42 UTC |
NVIDIA BioNeMo Core for Linux has a path traversal vulnerability (CWE-29) that allows a user to load a malicious file using a crafted path such as '\.. \filename'. Exploiting this vulnerability could lead to code execution, denial of service, information disclosure, and data tampering. The vulnerability has a high severity with a CVSS score of 8.8. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/20/2026, 17:47:28 UTC Added: 05/20/2026, 19:34:39 UTC |
0 CVE-2026-5627 is a critical path traversal vulnerability in mintplex-labs/anything-llm up to version 1.9.1, specifically in the AgentFlows component. It allows attackers with high privileges to bypass directory restrictions via crafted input to loadFlow and deleteFlow methods, potentially accessing or deleting arbitrary JSON files on the server. This can lead to disclosure of sensitive configuration files containing API keys or denial of service by deleting important files like package.json. The vulnerability is fixed in version 1.12.1. No official patch link or advisory is provided in the data, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 04/07/2026, 13:06:38 UTC Added: 04/07/2026, 13:46:13 UTC |
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extraction. An attacker with control over the tar.gz file can exploit this issue to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory in multi-tenant or shared cluster environments. Join the discussion | CVE Database V5 | 03/30/2026, 01:16:06 UTC Added: 03/30/2026, 01:38:16 UTC |
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2. Join the discussion | CVE Database V5 | 03/07/2026, 05:27:13 UTC Added: 03/07/2026, 05:46:06 UTC |
CVE-2025-66608 is a high-severity vulnerability in Yokogawa Electric Corporation's FAST/TOOLS software versions R9.01 to R10.04. The flaw stems from improper URL validation, allowing an unauthenticated attacker to send specially crafted requests to the web server and steal files. This vulnerability does not require user interaction or privileges, making it remotely exploitable over the network. The CVSS 4.0 base score is 8.7, indicating a significant risk to confidentiality without impacting integrity or availability. No known exploits are currently reported in the wild. European organizations using FAST/TOOLS in critical industrial control or SCADA environments could face data breaches and operational risks. Join the discussion | CVE Database V5 | 02/09/2026, 03:11:56 UTC Added: 02/09/2026, 03:31:15 UTC |
0 A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a malicious `name` parameter, leading to the server loading and executing arbitrary Python files from the upload directory for discussions. This issue arises due to the concatenation of `data.name` directly with `lollmsElfServer.lollms_paths.extensions_zoo_path` and its use as an argument for `ExtensionBuilder().build_extension()`. The server's handling of the `__init__.py` file in arbitrary locations, facilitated by `importlib.machinery.SourceFileLoader`, enables the execution of arbitrary code, such as command execution or creating a reverse-shell connection. This vulnerability affects the latest version of parisneo/lollms-webui and can lead to Remote Code Execution (RCE) when the application is exposed to an external endpoint or the UI, especially when bound to `0.0.0.0` or in `headless mode`. No user interaction is required for exploitation. Join the discussion | CVE Database V5 | 02/02/2026, 10:36:23 UTC Added: 02/02/2026, 11:00:08 UTC |
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. Join the discussion | CVE Database V5 | 10/11/2025, 08:51:04 UTC Added: 10/11/2025, 08:56:17 UTC |
0 A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `generic_utils.py`. This vulnerability allows an attacker to manipulate the `image_path` input to read arbitrary files on the server, including sensitive system files. The issue arises due to improper validation or sanitization of the file path, enabling path traversal sequences to access files outside the intended directory. The vulnerability is fixed in version 0.12.41. Join the discussion | CVE Database V5 | 07/07/2025, 12:21:10 UTC Added: 07/07/2025, 12:39:20 UTC |
Showing 1 to 10 of 10 results