Tag
Path Traversal Vulnerability in AcyMailing WordPress Plugin
1 rule 1 TTP 1 CVEThe AcyMailing WordPress plugin is vulnerable to unauthenticated directory traversal, allowing attackers to read arbitrary files on the server when the Embed images feature is enabled.
Directory Traversal in Direct Download for WooCommerce Plugin
1 TTP 1 CVEAn unauthenticated directory traversal vulnerability in the Direct Download for WooCommerce plugin (v1.19 and below) allows attackers to read arbitrary files from the underlying server.
C-MOR Video Surveillance Directory Traversal Vulnerability
2 rules 2 TTPsC-MOR Video Surveillance versions up to 6.0104 are vulnerable to an unauthenticated directory traversal attack in the show-movies.pml component, allowing remote attackers to read arbitrary files.
Directory Traversal Vulnerability in Cloud Commander
1 CVECloud Commander versions prior to 19.20.2 are vulnerable to a directory traversal flaw in REST file-operation and markdown endpoints, allowing unauthenticated attackers to read or write arbitrary files.
Unauthenticated Directory Traversal in Yamcs
2 rules 3 TTPs 1 CVEYamcs versions prior to 5.11.13 contain an unauthenticated directory traversal vulnerability in the HTTP request handling components that allows remote attackers to read arbitrary files from the underlying host.
Arbitrary File Deletion in Atarim AI Agency for WordPress Plugin
1 rule 1 TTP 1 CVEThe Atarim - AI Agency for WordPress plugin is vulnerable to arbitrary file deletion via directory traversal, enabling attackers with author-level access to delete sensitive files and potentially achieve remote code execution.
Path Traversal in @rhinostone/swig Template Engine
1 TTP 1 CVEThe @rhinostone/swig template engine (CVE-2023-25345) contains a path traversal vulnerability in its filesystem loader, allowing unauthenticated attackers to read arbitrary local files via include or extends tags.
Grafana Improper Access Control Information Disclosure Vulnerability
3 TTPs 1 CVEAn authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.
Directory Traversal and LFI in Ray 2.56.0
1 rule 2 TTPsRay 2.56.0 contains a directory traversal and local file inclusion vulnerability in the /api/v0/logs endpoint allowing unauthenticated attackers to read arbitrary files.
Directory Traversal in W3 Total Cache WordPress Plugin (CVE-2026-9282)
1 rule 3 TTPs 1 CVEAn unauthenticated directory traversal vulnerability (CVE-2026-9282) in all versions up to 2.9.4 of the W3 Total Cache plugin for WordPress allows attackers to read arbitrary files by manipulating the minify filename when manual minify mode is enabled.
CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server
2 TTPs 1 IOCAn unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.
Softneta MedDream PACS Server Premium Directory Traversal Vulnerability (CVE-2018-25374)
1 rule 1 TTP 1 CVESoftneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability, tracked as CVE-2018-25374, allowing unauthenticated attackers to read arbitrary files by manipulating the path parameter in requests to nocache.php.
Algernon handler.lua Discovery Leads to Remote Code Execution
2 rules 1 TTPAlgernon is vulnerable to remote code execution due to unbounded upward directory traversal when searching for `handler.lua`, allowing attackers with write access to parent directories to execute arbitrary code.
WordPress Anti-Malware Security and Bruteforce Firewall Directory Traversal Vulnerability
2 rules 1 TTP 1 CVEWordPress Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability (CVE-2021-47977) that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter in requests to admin-ajax.php.
Joomla com_fabrik Directory Traversal Vulnerability (CVE-2020-37219)
2 rules 1 TTP 1 CVEJoomla com_fabrik 3.9.11 is vulnerable to a directory traversal attack (CVE-2020-37219) where an unauthenticated attacker can list arbitrary files by manipulating the folder parameter in a GET request to the onAjax_files method, using path traversal sequences to access system directories outside the web root.
OpenClaw Arbitrary Directory Deletion Vulnerability
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.2 is vulnerable to arbitrary directory deletion in mirror mode, enabling attackers to delete remote directories by manipulating remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values.
compressing npm Package Symlink Bypass Vulnerability
3 rules 5 TTPs 1 CVE 1 IOCA vulnerability in the `compressing` npm package (<=v2.1.0) allows for arbitrary file overwrite via symlink path traversal, bypassing a previous patch for CVE-2026-24884.
LORIS Directory Traversal Vulnerability
2 rules 2 TTPs 1 CVELORIS, a neuroimaging research data management web application, is vulnerable to directory traversal (CVE-2026-35446) due to an incorrect order of operations in the FilesDownloadHandler, allowing authenticated attackers to access unauthorized files.
SiYuan Note Taking Application Directory Traversal Vulnerability
2 rules 1 TTPSiYuan note taking application is vulnerable to a directory traversal via the /api/file/readDir endpoint, which does not require authentication, allowing an attacker to enumerate the directory structure and retrieve file names, potentially leading to arbitrary document reading.
BuildKit Git URL Subdir Traversal Vulnerability
2 rules 1 TTPA vulnerability in BuildKit (fixed in v0.28.1) allows for potential file access outside the Git repository root due to insufficient validation of Git URL fragment subdirectories, potentially leading to privilege escalation.
Web Server Local File Inclusion Activity
2 rules 1 TTPThis rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.