Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-22 Clear
ID Title
CVE-2026-15789 Path Traversal in mobyproject (CVE-2026-15789)
path traversal in mobyproject (CVE-2026-15789). Data can be tampered with by attackers.
CVE-2026-15791 Path Traversal in c (CVE-2026-15791)
path traversal in c (CVE-2026-15791). Data can be tampered with by attackers.
CVE-2026-13693 Path Traversal in wordpress (CVE-2026-13693)
path traversal in wordpress (CVE-2026-13693). Confidential information can be exposed externally.
CVE-2026-53594 Path Traversal in laravel (CVE-2026-53594)
path traversal in laravel (CVE-2026-53594). Confidential information can be exposed externally.
CVE-2026-56452 Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
CVE-2026-56623 Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
CVE-2026-60027 Path Traversal in path-traversal (CVE-2026-60027)
path traversal in path-traversal (CVE-2026-60027). Risk of unauthorized operations or information disclosure.
CVE-2026-58484 Path Traversal in network-ai (CVE-2026-58484)
path traversal in network-ai (CVE-2026-58484). Data can be tampered with by attackers. Exploitable via ``path``. Mitigation: upgrade to `5.12.2` or later.
CVE-2026-58413 Path Traversal in network-ai (CVE-2026-58413)
path traversal in network-ai (CVE-2026-58413). Confidential information can be exposed externally. Exploitable via ``backupId``. Mitigation: upgrade to `5.12.2` or later.
CVE-2026-58414 Path Traversal in network-ai (CVE-2026-58414)
path traversal in network-ai (CVE-2026-58414). Confidential information can be exposed externally. Exploitable via ``lstatSync``. Mitigation: upgrade to `5.12.2` or later.
CVE-2026-58481 Path Traversal in network-ai (CVE-2026-58481)
path traversal in network-ai (CVE-2026-58481). Confidential information can be exposed externally. Exploitable via ``AgentRuntime``. Mitigation: upgrade to `5.12.2` or later.
CVE-2026-46555 Path Traversal in path-traversal (CVE-2026-46555)
path traversal in path-traversal (CVE-2026-46555). Confidential information can be exposed externally. Exploitable via `Host header`.
CVE-2026-32820 Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
CVE-2026-12701 Path Traversal in path-traversal (CVE-2026-12701)
path traversal in path-traversal (CVE-2026-12701). Data can be tampered with by attackers.
CVE-2026-52349 Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
CVE-2026-54910 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
CVE-2026-63739 Path Traversal in surrealdb (CVE-2026-63739)
path traversal in surrealdb (CVE-2026-63739). Confidential information can be exposed externally.
CVE-2026-12898 Path Traversal in wordpress (CVE-2026-12898)
path traversal in wordpress (CVE-2026-12898). Risk of unauthorized operations or information disclosure.
CVE-2026-16219 Path Traversal in path-traversal (CVE-2026-16219)
path traversal in path-traversal (CVE-2026-16219). Risk of unauthorized operations or information disclosure.
CVE-2025-71394 Path Traversal in surrealdb (CVE-2025-71394)
path traversal in surrealdb (CVE-2025-71394). Risk of unauthorized operations or information disclosure.
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-16088 Path Traversal in path-traversal (CVE-2026-16088)
path traversal in path-traversal (CVE-2026-16088). Risk of unauthorized operations or information disclosure.
CVE-2026-47871 Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-8859 Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
CVE-2026-7872 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
CVE-2026-15343 Path Traversal in path-traversal (CVE-2026-15343)
path traversal in path-traversal (CVE-2026-15343). Risk of unauthorized operations or information disclosure.
CVE-2026-15457 Path Traversal in wordpress (CVE-2026-15457)
path traversal in wordpress (CVE-2026-15457). Confidential information can be exposed externally.
CVE-2026-15160 Path Traversal in wordpress (CVE-2026-15160)
path traversal in wordpress (CVE-2026-15160). Risk of unauthorized operations or information disclosure.
CVE-2026-62229 Path Traversal in openclaw (CVE-2026-62229)
path traversal in openclaw (CVE-2026-62229). Successful exploitation can lead to full system takeover.
CVE-2026-39359 Path Traversal in path-traversal (CVE-2026-39359)
path traversal in path-traversal (CVE-2026-39359). Confidential information can be exposed externally.
CVE-2024-32386 Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
CVE-2026-55629 Path Traversal in whistle (CVE-2026-55629)
path traversal in whistle (CVE-2026-55629). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.3` or later.
CVE-2026-53535 Path Traversal in dos (CVE-2026-53535)
path traversal in dos (CVE-2026-53535). Risk of unauthorized operations or information disclosure.
CVE-2026-46336 Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
CVE-2026-13103 Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
CVE-2025-45870 Path Traversal in path-traversal (CVE-2025-45870)
path traversal in path-traversal (CVE-2025-45870). Confidential information can be exposed externally.
CVE-2026-59864 Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864). Risk of unauthorized operations or information disclosure. Exploitable via ``static_template.file``. Mitigation: upgrade to `1.29.1` or later.
CVE-2026-59866 Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59866)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59866). Risk of unauthorized operations or information disclosure. Exploitable via ``clientClassName``. Mitigation: upgrade to `1.29.1` or later.
CVE-2026-59867 Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867). Confidential information can be exposed externally. Exploitable via ``REMOTE_KIOTA_PROP``. Mitigation: upgrade to `1.29.1` or later.
CVE-2026-53598 Path Traversal in prompty (CVE-2026-53598)
path traversal in prompty (CVE-2026-53598). Confidential information can be exposed externally. Exploitable via ``prompty``. Mitigation: upgrade to `2.0.0b2` or later.
CVE-2026-59863 Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59863)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59863). Risk of unauthorized operations or information disclosure. Exploitable via ``outputPath``. Mitigation: upgrade to `1.29.1` or later.
CVE-2026-52890 Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled...
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The server/permissions/attachments.js...
CVE-2026-15921 Path Traversal in CVE-2026-15921 (CVE-2026-15921)
path traversal in CVE-2026-15921 (CVE-2026-15921). Risk of unauthorized operations or information disclosure. Exploitable via ``index.tab``.
CVE-2026-45533 Path Traversal in path-traversal (CVE-2026-45533)
path traversal in path-traversal (CVE-2026-45533). Risk of unauthorized operations or information disclosure.
CVE-2026-45419 Path Traversal in path-traversal (CVE-2026-45419)
path traversal in path-traversal (CVE-2026-45419). Risk of unauthorized operations or information disclosure.
CVE-2026-62947 Path Traversal in c (CVE-2026-62947)
path traversal in c (CVE-2026-62947). Confidential information can be exposed externally. Mitigation: upgrade to `25.12.5` or later.
CVE-2026-26032 Path Traversal in apache (CVE-2026-26032)
path traversal in apache (CVE-2026-26032). Risk of unauthorized operations or information disclosure.
CVE-2026-12997 Path Traversal in wordpress (CVE-2026-12997)
path traversal in wordpress (CVE-2026-12997). Confidential information can be exposed externally.
CVE-2026-20297 Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →