Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59195 |
|
Path Traversal in pnpm (CVE-2026-59195)
path traversal in pnpm (CVE-2026-59195). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59194 |
|
Path Traversal in pnpm (CVE-2026-59194)
path traversal in pnpm (CVE-2026-59194). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59152 |
|
Path Traversal in CVE-2026-59152 (CVE-2026-59152)
path traversal in CVE-2026-59152 (CVE-2026-59152). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.18` or later.
|
| CVE-2026-58203 |
|
Path Traversal in pydantic (CVE-2026-58203)
path traversal in pydantic (CVE-2026-58203). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.14.2` or later.
|
| CVE-2026-7185 |
|
Path Traversal in CVE-2026-7185 (CVE-2026-7185)
path traversal in CVE-2026-7185 (CVE-2026-7185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49297 |
|
Path Traversal in apache (CVE-2026-49297)
path traversal in apache (CVE-2026-49297). Data can be tampered with by attackers. Exploitable via ``GCSToSFTPOperator``.
|
| CVE-2026-14783 |
|
Path Traversal in path-traversal (CVE-2026-14783)
path traversal in path-traversal (CVE-2026-14783). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59510 |
|
Path Traversal in path-traversal (CVE-2026-59510)
path traversal in path-traversal (CVE-2026-59510). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14636 |
|
Path Traversal in path-traversal (CVE-2026-14636)
path traversal in path-traversal (CVE-2026-14636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14635 |
|
Path Traversal in path-traversal (CVE-2026-14635)
path traversal in path-traversal (CVE-2026-14635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14628 |
|
Path Traversal in path-traversal (CVE-2026-14628)
path traversal in path-traversal (CVE-2026-14628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28705 |
|
Path Traversal in CVE-2026-28705 (CVE-2026-28705)
path traversal in CVE-2026-28705 (CVE-2026-28705). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41124 |
|
Path Traversal in path-traversal (CVE-2026-41124)
path traversal in path-traversal (CVE-2026-41124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47896 |
|
Path Traversal in csharp (CVE-2026-47896)
path traversal in csharp (CVE-2026-47896). Confidential information can be exposed externally.
|
| CVE-2026-47897 |
|
Path Traversal in csharp (CVE-2026-47897)
path traversal in csharp (CVE-2026-47897). Data can be tampered with by attackers.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-14352 |
|
Path Traversal in wordpress (CVE-2026-14352)
path traversal in wordpress (CVE-2026-14352). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-14327 |
|
Path Traversal in wordpress (CVE-2026-14327)
path traversal in wordpress (CVE-2026-14327). Confidential information can be exposed externally.
|
| CVE-2026-13054 |
|
Path Traversal in path-traversal (CVE-2026-13054)
path traversal in path-traversal (CVE-2026-13054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-52830 |
|
Path Traversal in fast-mcp-telegram (CVE-2026-52830)
path traversal in fast-mcp-telegram (CVE-2026-52830). Confidential information can be exposed externally. Exploitable via ``telegram``. Mitigation: upgrade to `0.19.1` or later.
|
| CVE-2026-49253 |
|
Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-49244 |
|
Path Traversal in github.com/drakkan/sftpgo/v2 (CVE-2026-49244)
path traversal in github.com/drakkan/sftpgo/v2 (CVE-2026-49244). Confidential information can be exposed externally. Mitigation: upgrade to `2.7.3` or later.
|
| CVE-2026-50180 |
|
Path Traversal in langroid (CVE-2026-50180)
path traversal in langroid (CVE-2026-50180). Risk of unauthorized operations or information disclosure. Exploitable via ``SQLChatAgent``. Mitigation: upgrade to `0.64.0` or later.
|
| CVE-2026-50181 |
|
Path Traversal in langroid (CVE-2026-50181)
path traversal in langroid (CVE-2026-50181). Confidential information can be exposed externally. Exploitable via ``ReadFileTool``. Mitigation: upgrade to `0.64.0` or later.
|
| CVE-2026-55117 |
|
Path Traversal in path-traversal (CVE-2026-55117)
path traversal in path-traversal (CVE-2026-55117). Confidential information can be exposed externally.
|
| CVE-2026-55111 |
|
Path Traversal in path-traversal (CVE-2026-55111)
path traversal in path-traversal (CVE-2026-55111). Confidential information can be exposed externally.
|
| CVE-2026-54403 |
|
Path Traversal in path-traversal (CVE-2026-54403)
path traversal in path-traversal (CVE-2026-54403). Confidential information can be exposed externally.
|
| CVE-2026-54406 |
|
Path Traversal in path-traversal (CVE-2026-54406)
path traversal in path-traversal (CVE-2026-54406). Data can be tampered with by attackers.
|
| CVE-2026-9145 |
|
Path Traversal in wordpress (CVE-2026-9145)
path traversal in wordpress (CVE-2026-9145). Confidential information can be exposed externally.
|
| CVE-2026-13369 |
|
Path Traversal in wordpress (CVE-2026-13369)
path traversal in wordpress (CVE-2026-13369). Confidential information can be exposed externally.
|
| CVE-2026-13251 |
|
Path Traversal in wordpress (CVE-2026-13251)
path traversal in wordpress (CVE-2026-13251). Confidential information can be exposed externally.
|
| CVE-2026-14439 |
|
Path Traversal in path-traversal (CVE-2026-14439)
path traversal in path-traversal (CVE-2026-14439). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|
| CVE-2026-50163 |
|
Path Traversal in oras.land/oras-go/v2 (CVE-2026-50163)
path traversal in oras.land/oras-go/v2 (CVE-2026-50163). Confidential information can be exposed externally. Exploitable via ``ensureLinkPath``. Mitigation: upgrade to `2.6.2` or later.
|
| CVE-2026-58451 |
|
Path Traversal in csrf (CVE-2026-58451)
path traversal in csrf (CVE-2026-58451). Confidential information can be exposed externally.
|
| CVE-2026-49119 |
|
Path Traversal in path-traversal (CVE-2026-49119)
path traversal in path-traversal (CVE-2026-49119). Confidential information can be exposed externally.
|
| CVE-2026-5051 |
|
Path Traversal in vault (CVE-2026-5051)
path traversal in vault (CVE-2026-5051). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-20191 |
|
Path Traversal in cisco (CVE-2026-20191)
path traversal in cisco (CVE-2026-20191). Confidential information can be exposed externally.
|
| CVE-2026-53906 |
|
Path Traversal in path-traversal (CVE-2026-53906)
path traversal in path-traversal (CVE-2026-53906). Data can be tampered with by attackers.
|
| CVE-2026-56377 |
|
Path Traversal in imagemagick (CVE-2026-56377)
path traversal in imagemagick (CVE-2026-56377). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56233 |
|
Path Traversal in path-traversal (CVE-2026-56233)
path traversal in path-traversal (CVE-2026-56233). Confidential information can be exposed externally.
|
| CVE-2026-52868 |
|
Path Traversal in CVE-2026-52868 (CVE-2026-52868)
path traversal in CVE-2026-52868 (CVE-2026-52868). Confidential information can be exposed externally.
|
| CVE-2026-50003 |
|
Path Traversal in c (CVE-2026-50003)
path traversal in c (CVE-2026-50003). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11595 |
|
Path Traversal in ibm (CVE-2026-11595)
path traversal in ibm (CVE-2026-11595). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48796 |
|
Path Traversal in CefSharp.Common (CVE-2026-48796)
path traversal in CefSharp.Common (CVE-2026-48796). Confidential information can be exposed externally. Exploitable via ``FolderSchemeHandlerFactory``. Mitigation: upgrade to `148.0.90` or later.
|
| CVE-2026-58372 |
|
Path Traversal in path-traversal (CVE-2026-58372)
path traversal in path-traversal (CVE-2026-58372). Data can be tampered with by attackers.
|
| CVE-2026-58173 |
|
Path Traversal in path-traversal (CVE-2026-58173)
path traversal in path-traversal (CVE-2026-58173). Data can be tampered with by attackers.
|
| CVE-2026-58171 |
|
Path Traversal in CVE-2026-58171 (CVE-2026-58171)
path traversal in CVE-2026-58171 (CVE-2026-58171). Risk of unauthorized operations or information disclosure.
|