CVE-2026-66695
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-35
Not enough EPSS history yet.
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59181—18.6%
——6Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.9dCVE-2025-608357.8 HIG4.5%
——1An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.13dCVE-2026-497796.5 MED26.9%
——8Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal.
This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.9dCVE-2026-401289.0 CRI37.2%
——11SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.15dCVE-2026-243154.2 MED7.0%
——2SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.15dCVE-2026-456619.9 CRI48.1%
——14Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file write to remote server filesystems, automatic remote code execution via cron jobs, complete server compromise, data exfiltration without user interaction, and persistent backdoor installation. This vulnerability bypasses all container isolation on remote server deployments.16d