CWE-29
64 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-29page 2 of 2
- CVE-2024-7962HIGHCVSS 7.5EG 7.52024-10-29
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute pa…
- CVE-2024-8248HIGHCVSS 7.2EG 7.22025-03-20
A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from mana…
- CVE-2024-8537CRITICALCVSS 9.1EG 9.12025-03-20
A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This…
- CVE-2024-8769CRITICALCVSS 9.1EG 9.12025-03-20
A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is concatenated without …
- CVE-2024-8859HIGHCVSS 7.5EG 7.52025-03-20
A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs …
- CVE-2024-8982MEDIUMCVSS 6.2EG 6.22025-03-20
A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information su…
- CVE-2025-12790HIGHCVSS 7.4EG 7.42025-11-06
A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.
- CVE-2025-50184HIGHCVSS 7.1EG 0.02025-07-26
DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the en…
- CVE-2025-50185HIGHCVSS 7.0EG 0.02025-07-26
DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with application-level access can retrieve data from arbitrary fi…
- CVE-2025-58291LOWCVSS 3.3EG 3.32025-10-11
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- CVE-2025-6209HIGHCVSS 7.5EG 7.52025-07-07
A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `generic_utils.py`. This vulnerability allows an attacker to manipulate the `image_path` in…
- CVE-2025-66608HIGHCVSS 7.5EG 7.52026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected …
- CVE-2026-24217HIGHCVSS 8.8EG 8.82026-05-20
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosur…
- CVE-2026-5627HIGHCVSS 7.2EG 9.12026-04-07
A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper handling of user input in the `loadFlow` and `deleteFlow` met…
Map vulnerabilities like CWE-29 to your infrastructure
EchelonGraph correlates every CVE — across CWE-29 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →