PoC Archive PoC Archive

tag

Path Traversal

React Router Session Path Traversal (CVE-2025-61686)
CVE-2025-61686 web Unverified
CVE-2025-61686webCRITICAL 9.1Unverified2026-09-03Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130 binary Unverified
CVE-2025-55130binaryCRITICAL 9.1Unverified2026-09-03Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
CVE-2026-75604 web Unverified
CVE-2026-75604webCRITICAL 9Unverified2026-09-03UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908networkCRITICAL 10Patched2026-08-16Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 network Unverified
CVE-2026-47301networkCRITICAL 9.8Unverified2026-08-15Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106 binary Unverified
CVE-2026-17106binaryCRITICAL 9.8Unverified2026-08-15Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CVE-2025-61882webCRITICAL 9.8Patched2026-08-09Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory) web Patched
CVE-2026-65694webHIGH 7.5Patched2026-07-31Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CVE-2026-48282webCRITICAL 10Patched2026-07-19Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CVE-2026-56260webCRITICAL 9.1Patched2026-07-12ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
CVE-2023-38950webHIGH 7.5Patched2026-07-11Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CVE-2025-4632webCRITICAL 9.8Patched2026-07-06Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517 misc Patched
CVE-2025-4517miscCRITICAL 9.4Patched2026-07-06Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CVE-2025-49132webCRITICAL 10Patched2026-07-06Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
CVE-2025-52913 network Unverified
CVE-2025-52913networkCRITICAL 9.8Unverified2026-07-06FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CVE-2025-64446networkCRITICAL 9.8Unverified2026-07-06Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333) KEV EPSS 71%
CVE-2025-20333 network Unverified
CVE-2025-20333networkCRITICAL 9.9Unverified2026-07-06ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
CVE-2026-28286 web Unverified
CVE-2026-28286webCRITICALUnverified2026-07-05WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357) EPSS 33%
CVE-2026-1357 web Unverified
CVE-2026-1357webCRITICALUnverified2026-07-05Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
CVE-2026-37066 web Unverified
CVE-2026-37066webHIGHUnverified2026-07-05UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
CVE-2026-36851 misc Unverified
CVE-2026-36851miscHIGH 7.5Unverified2026-07-05TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653) network Unverified
CVE-2026-0651networkCRITICALUnverified2026-07-05Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx) web Patched
CVE-2026-25964webMEDIUM 4.9Patched2026-07-05Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CVE-2026-1056webCRITICALUnverified2026-07-05Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912 web Patched
CVE-2026-11912webHIGH 7.5Patched2026-07-05Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 web Unverified
CVE-2026-4350webHIGH 8.1Unverified2026-07-05OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156
CVE-2026-31156 hardware Unverified
CVE-2026-31156hardwareHIGHUnverified2026-07-05OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849 web Patched
CVE-2026-24849webCRITICAL 6.5Patched2026-07-05Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786 misc Patched
CVE-2026-29786miscHIGHPatched2026-07-05node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 misc Patched
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97miscHIGHPatched2026-07-05Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh) web Patched
CVE-2026-53519webINFOPatched2026-07-05MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483) EPSS 11%
CVE-2026-27483 web Patched
CVE-2026-27483webCRITICALPatched2026-07-05mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CVE-2026-27825webCRITICAL 9.3Patched2026-07-05LiquidJS Template Engine Path Traversal — CVE-2026-30952
CVE-2026-30952 (GHSA-wmfp-5q7x-987x) misc Patched
CVE-2026-30952miscHIGH 8.7Patched2026-07-05Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
CVE-2026-42048 (GHSA-9whx-c884-c68q) web Patched
CVE-2026-42048webHIGHPatched2026-07-05iOS App Intents Path Traversal — CVE-2026-28995
CVE-2026-28995 misc Patched
CVE-2026-28995miscHIGHPatched2026-07-05InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CVE-2026-23491webCRITICALPatched2026-07-05Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866 web Patched
CVE-2026-48866webCRITICAL 9.6Patched2026-07-05Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2) web Patched
CVE-2026-24135webHIGH 7.5Patched2026-07-05Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813 web Patched
CVE-2026-52813webINFOPatched2026-07-05FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CVE-2026-25895webCRITICAL 9.8Patched2026-07-05EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656 web Patched
CVE-2026-33656webCRITICALPatched2026-07-05Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751) web Patched
CVE-2026-2749webCRITICALPatched2026-07-05Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815 web Unverified
CVE-2026-6815webHIGHUnverified2026-07-05BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
CVE-2026-39387webHIGHPatched2026-07-05BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515 web Unverified
CVE-2026-7515webCRITICAL 9.8Unverified2026-07-05ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
CVE-2026-32731 web Patched
CVE-2026-32731webHIGHPatched2026-07-05Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
CVE-2026-39973 misc Patched
CVE-2026-39973miscHIGHPatched2026-07-05AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CVE-2026-21440webCRITICAL 9.2Patched2026-07-05Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudMEDIUMUnverified2026-07-03WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088) KEV RW EPSS 95%
CVE-2025-8088 misc Patched
CVE-2025-8088miscHIGH 8.4Patched2026-07-01Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262) KEV EPSS 28%
CVE-2026-20262 network Unverified
CVE-2026-20262networkMEDIUM 6.5Unverified2026-07-01Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910) KEV EPSS 85%
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network Patched
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910networkCRITICAL 10Patched2026-06-28Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400) KEV RW EPSS 100%
CVE-2024-3400 web Patched
CVE-2024-3400webCRITICAL 10Patched2026-05-17Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108) KEV EPSS 98%
CVE-2025-0108 web Patched
CVE-2025-0108webCRITICAL 9.1Patched2026-05-16WinRAR Archive Extraction Path Traversal (CVE-2025-6218) KEV EPSS 90%
CVE-2025-6218 misc Unverified
CVE-2025-6218miscHIGHUnverified2026-05-15