Skip to main content

Threats Tagged 'cwe-36'

View all threats tagged with 'cwe-36'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-36

Threats Tagged 'cwe-36'

Click on any threat for detailed analysis and mitigation recommendations

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory components to escape that directory. The resulting path is passed to the configured editor, which can access or modify files outside the hooks directory with the privileges of the uniget process account. This issue is fixed in version 0.27.6.

Join the discussion

Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

Join the discussion

CVE-2026-82092 is an absolute path traversal vulnerability in IBM DataStage on Cloud Pak for Data version 5.4.0.0. This flaw allows a remote authenticated attacker to access sensitive information by exploiting improper validation of file paths. The vulnerability has a high severity rating with a CVSS score of 8.8, indicating significant impact on confidentiality, integrity, and availability.

Join the discussion

A path traversal vulnerability in Plesk's Backup Manager allows an authenticated customer to write arbitrary files as root. This vulnerability can lead to complete system compromise due to the high privileges involved.

Join the discussion

GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.

Join the discussion

CVE-2026-68896 is a high-severity vulnerability in the Microsoft Windows Search Component of Windows 11 version 23H2. It involves an absolute path traversal flaw that allows an authorized local attacker to elevate privileges. The vulnerability affects multiple specific builds of Windows 11 version 23H2. An official fix is available from Microsoft.

Join the discussion

CVE-2026-69612 is an absolute path traversal vulnerability in Windows Error Reporting on Microsoft Windows 10 Version 1607 and related versions. This flaw allows an authorized local attacker to elevate privileges. The vulnerability has a high severity rating with a CVSS score of 7.8. Microsoft has issued an official fix for this vulnerability.

Join the discussion

CVE-2026-47630 is an absolute path traversal vulnerability in NVIDIA Triton Inference Server for Linux. An attacker with limited privileges could exploit this flaw to cause absolute path traversal, potentially leading to code execution. The vulnerability has a medium severity rating with a CVSS score of 5.5. There is no indication of known exploits in the wild or an official patch available at this time.

Join the discussion

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.

Join the discussion

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue.

Join the discussion

Showing 1 to 10 of 72 results

Filters:Tag: cwe-36
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses