Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15789 |
|
Path Traversal in mobyproject (CVE-2026-15789)
path traversal in mobyproject (CVE-2026-15789). Data can be tampered with by attackers.
|
| CVE-2026-15791 |
|
Path Traversal in c (CVE-2026-15791)
path traversal in c (CVE-2026-15791). Data can be tampered with by attackers.
|
| CVE-2026-13693 |
|
Path Traversal in wordpress (CVE-2026-13693)
path traversal in wordpress (CVE-2026-13693). Confidential information can be exposed externally.
|
| CVE-2026-53594 |
|
Path Traversal in laravel (CVE-2026-53594)
path traversal in laravel (CVE-2026-53594). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-60027 |
|
Path Traversal in path-traversal (CVE-2026-60027)
path traversal in path-traversal (CVE-2026-60027). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58484 |
|
Path Traversal in network-ai (CVE-2026-58484)
path traversal in network-ai (CVE-2026-58484). Data can be tampered with by attackers. Exploitable via ``path``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58413 |
|
Path Traversal in network-ai (CVE-2026-58413)
path traversal in network-ai (CVE-2026-58413). Confidential information can be exposed externally. Exploitable via ``backupId``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58414 |
|
Path Traversal in network-ai (CVE-2026-58414)
path traversal in network-ai (CVE-2026-58414). Confidential information can be exposed externally. Exploitable via ``lstatSync``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58481 |
|
Path Traversal in network-ai (CVE-2026-58481)
path traversal in network-ai (CVE-2026-58481). Confidential information can be exposed externally. Exploitable via ``AgentRuntime``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-46555 |
|
Path Traversal in path-traversal (CVE-2026-46555)
path traversal in path-traversal (CVE-2026-46555). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-32820 |
|
Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
|
| CVE-2026-12701 |
|
Path Traversal in path-traversal (CVE-2026-12701)
path traversal in path-traversal (CVE-2026-12701). Data can be tampered with by attackers.
|
| CVE-2026-52349 |
|
Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54910 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
|
| CVE-2026-63739 |
|
Path Traversal in surrealdb (CVE-2026-63739)
path traversal in surrealdb (CVE-2026-63739). Confidential information can be exposed externally.
|
| CVE-2026-12898 |
|
Path Traversal in wordpress (CVE-2026-12898)
path traversal in wordpress (CVE-2026-12898). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16219 |
|
Path Traversal in path-traversal (CVE-2026-16219)
path traversal in path-traversal (CVE-2026-16219). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71394 |
|
Path Traversal in surrealdb (CVE-2025-71394)
path traversal in surrealdb (CVE-2025-71394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15631 |
|
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
|
| CVE-2026-16088 |
|
Path Traversal in path-traversal (CVE-2026-16088)
path traversal in path-traversal (CVE-2026-16088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47871 |
|
Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-8859 |
|
Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7872 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
|
| CVE-2026-7667 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
|
| CVE-2026-15343 |
|
Path Traversal in path-traversal (CVE-2026-15343)
path traversal in path-traversal (CVE-2026-15343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15457 |
|
Path Traversal in wordpress (CVE-2026-15457)
path traversal in wordpress (CVE-2026-15457). Confidential information can be exposed externally.
|
| CVE-2026-15160 |
|
Path Traversal in wordpress (CVE-2026-15160)
path traversal in wordpress (CVE-2026-15160). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62229 |
|
Path Traversal in openclaw (CVE-2026-62229)
path traversal in openclaw (CVE-2026-62229). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39359 |
|
Path Traversal in path-traversal (CVE-2026-39359)
path traversal in path-traversal (CVE-2026-39359). Confidential information can be exposed externally.
|
| CVE-2024-32386 |
|
Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
|
| CVE-2026-55629 |
|
Path Traversal in whistle (CVE-2026-55629)
path traversal in whistle (CVE-2026-55629). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.3` or later.
|
| CVE-2026-53535 |
|
Path Traversal in dos (CVE-2026-53535)
path traversal in dos (CVE-2026-53535). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46336 |
|
Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
|
| CVE-2026-13103 |
|
Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
|
| CVE-2025-45870 |
|
Path Traversal in path-traversal (CVE-2025-45870)
path traversal in path-traversal (CVE-2025-45870). Confidential information can be exposed externally.
|
| CVE-2026-59864 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864). Risk of unauthorized operations or information disclosure. Exploitable via ``static_template.file``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-59866 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59866)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59866). Risk of unauthorized operations or information disclosure. Exploitable via ``clientClassName``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-59867 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867). Confidential information can be exposed externally. Exploitable via ``REMOTE_KIOTA_PROP``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-53598 |
|
Path Traversal in prompty (CVE-2026-53598)
path traversal in prompty (CVE-2026-53598). Confidential information can be exposed externally. Exploitable via ``prompty``. Mitigation: upgrade to `2.0.0b2` or later.
|
| CVE-2026-59863 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59863)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59863). Risk of unauthorized operations or information disclosure. Exploitable via ``outputPath``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-52890 |
|
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled...
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The server/permissions/attachments.js...
|
| CVE-2026-15921 |
|
Path Traversal in CVE-2026-15921 (CVE-2026-15921)
path traversal in CVE-2026-15921 (CVE-2026-15921). Risk of unauthorized operations or information disclosure. Exploitable via ``index.tab``.
|
| CVE-2026-45533 |
|
Path Traversal in path-traversal (CVE-2026-45533)
path traversal in path-traversal (CVE-2026-45533). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45419 |
|
Path Traversal in path-traversal (CVE-2026-45419)
path traversal in path-traversal (CVE-2026-45419). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62947 |
|
Path Traversal in c (CVE-2026-62947)
path traversal in c (CVE-2026-62947). Confidential information can be exposed externally. Mitigation: upgrade to `25.12.5` or later.
|
| CVE-2026-26032 |
|
Path Traversal in apache (CVE-2026-26032)
path traversal in apache (CVE-2026-26032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12997 |
|
Path Traversal in wordpress (CVE-2026-12997)
path traversal in wordpress (CVE-2026-12997). Confidential information can be exposed externally.
|
| CVE-2026-20297 |
|
Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.
|