CWE-23

CWE-23 · 5 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-23, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-8066

    A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful e…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-18907

    Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-93537public PoC

    A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment t…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-13224

    A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-102252public PoC

    A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images,…

    AI risk analysis on Exploit-DB.ai →