CWE-29: CWE-29

32
Total CVEs
12
Critical
19
High
8.3
Avg CVSS

Yearly Trend

2026
2
2025
11
2024
15
2023
4

Top Affected Vendors

1 Lollms 6
2 Lfprojects 4
3 Mintplexlabs 2
4 Hsclabs 1
5 Yokogawa 1
6 Weintek 1
7 Dell 1
8 Vertaai 1
9 Librechat 1
10 Openwebui 1

All CWE-29 CVEs (32)

CVE-2024-2083
9.9

A directory traversal vulnerability in the zenml-io/zenml repository allows attackers to read arbitrary files on the server by manipulating the 'logs'...

Apr 16, 2024
CVE-2024-6396
9.8

This vulnerability in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the server and exfiltrate arbitrary data by manipul...

Jul 12, 2024
CVE-2024-5443
9.8

This CVE describes a path traversal vulnerability in parisneo/lollms software that allows remote code execution. Attackers can exploit the /mount_exte...

Jun 22, 2024
CVE-2024-4320
9.8

This CVE-2024-4320 is a critical remote code execution vulnerability in the parisneo/lollms-webui application. Attackers can exploit the '/install_ext...

Jun 6, 2024
CVE-2024-2624
9.8

This vulnerability allows attackers to perform path traversal and arbitrary file uploads in the lollms-webui application by manipulating the 'path' pa...

Jun 6, 2024
CVE-2024-2358
9.8

A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code by exploiting ins...

May 16, 2024
CVE-2023-2780
9.8

This CVE describes a path traversal vulnerability in MLflow where attackers can use '\..\filename' sequences to access files outside intended director...

May 17, 2023
CVE-2024-2356
9.6

This CVE describes a Local File Inclusion vulnerability in the lollms-webui application that allows attackers to execute arbitrary Python code remotel...

Feb 2, 2026
CVE-2024-3573
9.3

This vulnerability in MLflow allows attackers to perform Local File Inclusion (LFI) by exploiting improper URI parsing in the 'is_local_uri' function....

Apr 16, 2024
CVE-2023-0104
9.3

This vulnerability in Weintek EasyBuilder Pro allows attackers to execute arbitrary code or access sensitive data by tricking users into opening malic...

Feb 22, 2023
CVE-2024-8537
9.1

A path traversal vulnerability in modelscope/agentscope's /delete-workflow endpoint allows attackers to delete arbitrary files from the filesystem by ...

Mar 20, 2025
CVE-2024-7957
9.1

This vulnerability allows attackers to overwrite or create arbitrary files on systems running danswer-ai/danswer with ZulipConnector enabled. Attacker...

Mar 20, 2025
CVE-2024-12389
8.8

A path traversal vulnerability in binary-husky/gpt_academic allows attackers to write arbitrary files outside the intended extraction directory when p...

Mar 20, 2025
CVE-2024-11170
8.8

A path traversal vulnerability in danny-avila/librechat allows attackers to write files to arbitrary locations on the server due to improper sanitizat...

Mar 20, 2025
CVE-2024-34470
8.6

An unauthenticated path traversal vulnerability in HSC Mailinspector allows attackers to read arbitrary files on the server without authentication. Th...

May 6, 2024
CVE-2024-3435
8.4

A path traversal vulnerability in the parisneo/lollms-webui application allows attackers to manipulate configuration settings via specially crafted JS...

May 16, 2024
CVE-2025-66608
7.5

A path traversal vulnerability in Yokogawa's FAST/TOOLS software allows attackers to bypass URL validation and access arbitrary files on the web serve...

Feb 9, 2026
CVE-2025-6209
7.5

A path traversal vulnerability in run-llama/llama_index versions 0.12.27 through 0.12.40 allows attackers to read arbitrary files on the server by man...

Jul 7, 2025
CVE-2024-8859
EPSS 26.9% 7.5

A path traversal vulnerability in MLflow 2.15.1 allows attackers to read arbitrary files when the DBFS service is configured and mounted locally. This...

Mar 20, 2025
CVE-2024-7962
7.5

An arbitrary file read vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows attackers to read sensitive files on the server by exploiti...

Oct 29, 2024
CVE-2024-6394
7.5

A Local File Inclusion vulnerability in parisneo/lollms-webui allows attackers to read arbitrary files on the server through path traversal. This affe...

Sep 30, 2024
CVE-2024-2178
7.5

This path traversal vulnerability in parisneo/lollms-webui allows attackers to read arbitrary files by manipulating parameters in the 'copy_to_custom_...

Jun 2, 2024
CVE-2024-1561
7.5

This vulnerability in gradio allows attackers to read any file on the filesystem by exploiting the /component_server endpoint. It affects gradio appli...

Apr 16, 2024
CVE-2023-6909
7.5

This path traversal vulnerability in MLflow allows attackers to access arbitrary files on the server by using '\..\filename' sequences in requests. It...

Dec 18, 2023
CVE-2023-6023
7.5

This Local File Inclusion (LFI) vulnerability in ModelDB allows attackers to read arbitrary files on the server filesystem by manipulating the artifac...

Nov 16, 2023
CVE-2025-12790
7.4

CVE-2025-12790 is a vulnerability in Rubygem MQTT where default configurations lack hostname validation, enabling Man-in-the-Middle attacks. This allo...

Nov 6, 2025
CVE-2024-8248
7.2

A path traversal vulnerability in the normalizePath function of mintplex-labs/anything-llm allows attackers to read and write arbitrary files within t...

Mar 20, 2025
CVE-2024-7033
7.2

This vulnerability allows attackers to write arbitrary files to the server's filesystem by manipulating file paths in the download_model endpoint. It ...

Mar 20, 2025
CVE-2024-21518
7.2

This Zip Slip vulnerability in OpenCart's marketplace installer allows attackers to upload malicious ZIP archives that can extract files to arbitrary ...

Jun 22, 2024
CVE-2024-5211
7.2

A path traversal vulnerability in mintplex-labs/anything-llm allows authenticated managers to bypass path normalization and access, delete, or overwri...

Jun 12, 2024
CVE-2024-51534
7.1

A local path traversal vulnerability in Dell PowerProtect DD allows low-privileged users to overwrite OS files, potentially causing denial of service....

Feb 1, 2025
CVE-2024-8982
6.2

This Local File Inclusion vulnerability in OpenLLM 0.6.10 allows attackers to read sensitive server files through the web application. Attackers can a...

Mar 20, 2025

About CWE-29 (CWE-29)

Our database tracks 32 CVEs classified as CWE-29, with 12 rated critical and 19 rated high severity. The average CVSS score for CWE-29 vulnerabilities is 8.3.

External reference: View CWE-29 on MITRE CWE →

Monitor CWE-29 Vulnerabilities

Get alerted when new CWE-29 CVEs affect your infrastructure.

Start Monitoring Free