Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58171 |
|
Path Traversal in CVE-2026-58171 (CVE-2026-58171)
path traversal in CVE-2026-58171 (CVE-2026-58171). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58170 |
|
Path Traversal in path-traversal (CVE-2026-58170)
path traversal in path-traversal (CVE-2026-58170). Data can be tampered with by attackers.
|
| CVE-2026-48314 |
|
Path Traversal in path-traversal (CVE-2026-48314)
path traversal in path-traversal (CVE-2026-48314). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48313 |
|
Path Traversal in path-traversal (CVE-2026-48313)
path traversal in path-traversal (CVE-2026-48313). Confidential information can be exposed externally.
|
| CVE-2026-48282 KEV |
|
[KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-58015 |
|
Path Traversal in path-traversal (CVE-2026-58015)
path traversal in path-traversal (CVE-2026-58015). Confidential information can be exposed externally.
|
| CVE-2026-57079 |
|
Path Traversal in path-traversal (CVE-2026-57079)
path traversal in path-traversal (CVE-2026-57079). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11367 |
|
Path Traversal in wordpress (CVE-2026-11367)
path traversal in wordpress (CVE-2026-11367). Confidential information can be exposed externally.
|
| CVE-2026-58302 |
|
Path Traversal in path-traversal (CVE-2026-58302)
path traversal in path-traversal (CVE-2026-58302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12243 |
|
Path Traversal in nltk (CVE-2026-12243)
path traversal in nltk (CVE-2026-12243). Confidential information can be exposed externally. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-8023 |
|
Path Traversal in c (CVE-2026-8023)
path traversal in c (CVE-2026-8023). Confidential information can be exposed externally.
|
| CVE-2026-43732 |
|
Path Traversal in apple (CVE-2026-43732)
path traversal in apple (CVE-2026-43732). Confidential information can be exposed externally.
|
| CVE-2026-36848 |
|
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
|
| CVE-2026-11720 |
|
Path Traversal in path-traversal (CVE-2026-11720)
path traversal in path-traversal (CVE-2026-11720). Confidential information can be exposed externally.
|
| CVE-2026-13748 |
|
Path Traversal in snowflake (CVE-2026-13748)
path traversal in snowflake (CVE-2026-13748). Confidential information can be exposed externally.
|
| CVE-2026-57331 |
|
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
|
| CVE-2026-55607 |
|
Path Traversal in @anthropic-ai/claude-code (CVE-2026-55607)
path traversal in @anthropic-ai/claude-code (CVE-2026-55607). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.163` or later.
|
| CVE-2026-40521 |
|
Path Traversal in path-traversal (CVE-2026-40521)
path traversal in path-traversal (CVE-2026-40521). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57346 |
|
Path Traversal in path-traversal (CVE-2026-57346)
path traversal in path-traversal (CVE-2026-57346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57966 |
|
Path Traversal in path-traversal (CVE-2026-57966)
path traversal in path-traversal (CVE-2026-57966). Data can be tampered with by attackers.
|
| CVE-2026-13528 |
|
Path Traversal in vue (CVE-2026-13528)
path traversal in vue (CVE-2026-13528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13509 |
|
Path Traversal in path-traversal (CVE-2026-13509)
path traversal in path-traversal (CVE-2026-13509). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13503 |
|
Path Traversal in path-traversal (CVE-2026-13503)
path traversal in path-traversal (CVE-2026-13503). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28701 |
|
Path Traversal in daktronics (CVE-2026-28701)
path traversal in daktronics (CVE-2026-28701). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55700 |
|
Path Traversal in pnpm (CVE-2026-55700)
path traversal in pnpm (CVE-2026-55700). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55699 |
|
Path Traversal in pnpm (CVE-2026-55699)
path traversal in pnpm (CVE-2026-55699). Risk of unauthorized operations or information disclosure. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-50015 |
|
Path Traversal in pnpm (CVE-2026-50015)
path traversal in pnpm (CVE-2026-50015). Data can be tampered with by attackers. Exploitable via ``patchedDependencies``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-49984 |
|
Path Traversal in kestra (CVE-2026-49984)
path traversal in kestra (CVE-2026-49984). Confidential information can be exposed externally. Exploitable via `GET /api/v1/{tenant}/executions/{executionId}/file`. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-45807 |
|
Path Traversal in kestra (CVE-2026-45807)
path traversal in kestra (CVE-2026-45807). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.43` or later.
|
| CVE-2026-29509 |
|
Path Traversal in path-traversal (CVE-2026-29509)
path traversal in path-traversal (CVE-2026-29509). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49991 |
|
Path Traversal in path-traversal (CVE-2026-49991)
path traversal in path-traversal (CVE-2026-49991). Data can be tampered with by attackers.
|
| CVE-2026-56876 |
|
Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-55677 |
|
Path Traversal in github.com/labstack/echo/v5 (CVE-2026-55677)
path traversal in github.com/labstack/echo/v5 (CVE-2026-55677). Confidential information can be exposed externally. Exploitable via ``StaticDirectoryHandler``. Mitigation: upgrade to `5.2.0` or later.
|
| CVE-2026-44024 |
|
Path Traversal in fluentd (CVE-2026-44024)
path traversal in fluentd (CVE-2026-44024). Successful exploitation can lead to full system takeover. Exploitable via ``path``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-57321 |
|
Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.
Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.
|
| CVE-2026-56066 |
|
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
|
| CVE-2025-64152 |
|
Path Traversal in apache (CVE-2025-64152)
path traversal in apache (CVE-2025-64152). Confidential information can be exposed externally.
|
| CVE-2025-55017 |
|
Path Traversal in apache (CVE-2025-55017)
path traversal in apache (CVE-2025-55017). Confidential information can be exposed externally.
|
| CVE-2026-13426 |
|
Path Traversal in c (CVE-2026-13426)
path traversal in c (CVE-2026-13426). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57872 |
|
Path Traversal in path-traversal (CVE-2026-57872)
path traversal in path-traversal (CVE-2026-57872). Confidential information can be exposed externally.
|
| CVE-2026-40084 |
|
Path Traversal in path-traversal (CVE-2026-40084)
path traversal in path-traversal (CVE-2026-40084). Confidential information can be exposed externally.
|
| CVE-2026-56445 |
|
Path Traversal in c (CVE-2026-56445)
path traversal in c (CVE-2026-56445). Data can be tampered with by attackers.
|
| CVE-2026-55667 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667). Data can be tampered with by attackers. Exploitable via `GET /api/raw/link/secret.txt`. Mitigation: upgrade to `2.63.16` or later.
|
| CVE-2026-54917 |
|
Path Traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917)
path traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917). Confidential information can be exposed externally. Exploitable via `GET /bucket-A/../evil-bucket/key`. Mitigation: upgrade to `0.0.0-20260526080459-dd1b4287899e` or later.
|
| CVE-2026-54250 |
|
Path Traversal in github.com/k3s-io/k3s (CVE-2026-54250)
path traversal in github.com/k3s-io/k3s (CVE-2026-54250). Data can be tampered with by attackers. Exploitable via ``GODEBUG``. Mitigation: upgrade to `1.33.10` or later.
|
| CVE-2026-50548 |
|
Path Traversal in anysphere (CVE-2026-50548)
path traversal in anysphere (CVE-2026-50548). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0` or later.
|
| CVE-2026-9083 |
|
Path Traversal in redhat (CVE-2026-9083)
path traversal in redhat (CVE-2026-9083). Confidential information can be exposed externally.
|
| CVE-2026-45233 |
|
Path Traversal in path-traversal (CVE-2026-45233)
path traversal in path-traversal (CVE-2026-45233). Data can be tampered with by attackers.
|
| CVE-2026-48944 |
|
Path Traversal in joomlaworks (CVE-2026-48944)
path traversal in joomlaworks (CVE-2026-48944). Confidential information can be exposed externally. Exploitable via ``configuration.php``.
|
| CVE-2026-55439 |
|
Path Traversal in path-traversal (CVE-2026-55439)
path traversal in path-traversal (CVE-2026-55439). Confidential information can be exposed externally. Exploitable via `GET /apis/console.api.migration.halo.run/v1alpha1/backups/{name}/files/{filename}`. Mitigation: upgrade to `2.24.3` or later.
|