Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: path-traversal Clear
ID Title
CVE-2025-41271 Vulnerability in path-traversal (CVE-2025-41271)
vulnerability in path-traversal (CVE-2025-41271). Confidential information can be exposed externally.
CVE-2026-9559 Path Traversal in mautic/core (CVE-2026-9559)
path traversal in mautic/core (CVE-2026-9559). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.2` or later.
CVE-2026-10044 Vulnerability in path-traversal (CVE-2026-10044)
vulnerability in path-traversal (CVE-2026-10044). Confidential information can be exposed externally. Exploitable via `GET /api/prompts/{filename}`.
CVE-2026-49128 Path Traversal in path-traversal (CVE-2026-49128)
path traversal in path-traversal (CVE-2026-49128). Confidential information can be exposed externally.
CVE-2026-32847 Path Traversal in path-traversal (CVE-2026-32847)
path traversal in path-traversal (CVE-2026-32847). Confidential information can be exposed externally. Exploitable via `GET /{full_path`.
CVE-2026-33462 Path Traversal in elk (CVE-2026-33462)
path traversal in elk (CVE-2026-33462). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.19.16, 9.3.5` or later.
CVE-2026-47144 Path Traversal in shamefile (CVE-2026-47144)
path traversal in shamefile (CVE-2026-47144). Confidential information can be exposed externally. Exploitable via ``shamefile.yaml``. Mitigation: upgrade to `0.1.7` or later.
CVE-2026-45774 Path Traversal in compliance-trestle (CVE-2026-45774)
path traversal in compliance-trestle (CVE-2026-45774). Risk of unauthorized operations or information disclosure. Exploitable via ``trestle_root``. Mitigation: upgrade to `3.12.2` or later.
CVE-2026-49238 Path Traversal in cpp (CVE-2026-49238)
path traversal in cpp (CVE-2026-49238). Confidential information can be exposed externally.
CVE-2025-48977 Vulnerability in org.apache.ignite:ignite-core (CVE-2025-48977)
vulnerability in org.apache.ignite:ignite-core (CVE-2025-48977). Confidential information can be exposed externally. Mitigation: upgrade to `2.18.0` or later.
CVE-2026-9804 Vulnerability in kubevirt.io/kubevirt (CVE-2026-9804)
vulnerability in kubevirt.io/kubevirt (CVE-2026-9804). Confidential information can be exposed externally.
CVE-2026-6455 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-6455)
vulnerability in wordpress (CVE-2026-6455). Data can be tampered with by attackers.
CVE-2026-46402 Path Traversal in path-traversal (CVE-2026-46402)
path traversal in path-traversal (CVE-2026-46402). Data can be tampered with by attackers.
CVE-2026-45725 Vulnerability in compliance-trestle (CVE-2026-45725)
vulnerability in compliance-trestle (CVE-2026-45725). Risk of unauthorized operations or information disclosure. Exploitable via ``sys.path``. Mitigation: upgrade to `3.12.2` or later.
CVE-2026-45309 Path Traversal in asyncssh (CVE-2026-45309)
path traversal in asyncssh (CVE-2026-45309). Data can be tampered with by attackers. Exploitable via ``AuthorizedKeysFile``. Mitigation: upgrade to `2.23.0` or later.
CVE-2026-8361 Vulnerability in path-traversal (CVE-2026-8361)
vulnerability in path-traversal (CVE-2026-8361). Confidential information can be exposed externally.
CVE-2026-49009 Path Traversal in path-traversal (CVE-2026-49009)
path traversal in path-traversal (CVE-2026-49009). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-47118 Path Traversal in path-traversal (CVE-2026-47118)
path traversal in path-traversal (CVE-2026-47118). Confidential information can be exposed externally.
CVE-2026-48544 Path Traversal in taipy (CVE-2026-48544)
path traversal in taipy (CVE-2026-48544). Confidential information can be exposed externally.
CVE-2026-42756 Path Traversal in path-traversal (CVE-2026-42756)
path traversal in path-traversal (CVE-2026-42756). Successful exploitation can lead to full system takeover.
CVE-2026-42757 Path Traversal in path-traversal (CVE-2026-42757)
path traversal in path-traversal (CVE-2026-42757). Successful exploitation can lead to full system takeover.
CVE-2026-42737 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
CVE-2024-47267 Path Traversal in path-traversal (CVE-2024-47267)
path traversal in path-traversal (CVE-2024-47267). Risk of unauthorized operations or information disclosure.
CVE-2026-44705 Path Traversal in tmp (CVE-2026-44705)
path traversal in tmp (CVE-2026-44705). Data can be tampered with by attackers. Exploitable via ``prefix``. Mitigation: upgrade to `0.2.6` or later.
CVE-2026-9312 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9312)
SSRF in ssrf (CVE-2026-9312). Confidential information can be exposed externally.
CVE-2026-44177 Path Traversal in getkirby/cms (CVE-2026-44177)
path traversal in getkirby/cms (CVE-2026-44177). Risk of unauthorized operations or information disclosure. Exploitable via ``Users``. Mitigation: upgrade to `5.4.1` or later.
CVE-2026-48047 Vulnerability in org.xwiki.platform:xwiki-platform-webjars-api (CVE-2026-48047)
vulnerability in org.xwiki.platform:xwiki-platform-webjars-api (CVE-2026-48047). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.10.3` or later.
CVE-2026-42448 Path Traversal in magic-wormhole (CVE-2026-42448)
path traversal in magic-wormhole (CVE-2026-42448). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.24.0` or later.
CVE-2026-40384 Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-9550 Path Traversal in path-traversal (CVE-2026-9550)
path traversal in path-traversal (CVE-2026-9550). Risk of unauthorized operations or information disclosure.
CVE-2026-9472 Path Traversal in path-traversal (CVE-2026-9472)
path traversal in path-traversal (CVE-2026-9472). Risk of unauthorized operations or information disclosure.
CVE-2026-9473 Path Traversal in c (CVE-2026-9473)
path traversal in c (CVE-2026-9473). Risk of unauthorized operations or information disclosure.
CVE-2026-9467 Path Traversal in path-traversal (CVE-2026-9467)
path traversal in path-traversal (CVE-2026-9467). Risk of unauthorized operations or information disclosure.
CVE-2026-9468 Path Traversal in path-traversal (CVE-2026-9468)
path traversal in path-traversal (CVE-2026-9468). Risk of unauthorized operations or information disclosure.
CVE-2018-25374 Path Traversal in c (CVE-2018-25374)
path traversal in c (CVE-2018-25374). Confidential information can be exposed externally.
CVE-2018-25365 Path Traversal in path-traversal (CVE-2018-25365)
path traversal in path-traversal (CVE-2018-25365). Confidential information can be exposed externally.
CVE-2026-7766 Path Traversal in path-traversal (CVE-2026-7766)
path traversal in path-traversal (CVE-2026-7766). Risk of unauthorized operations or information disclosure.
CVE-2026-9351 Path Traversal in path-traversal (CVE-2026-9351)
path traversal in path-traversal (CVE-2026-9351). Risk of unauthorized operations or information disclosure.
CVE-2026-36227 Path Traversal in path-traversal (CVE-2026-36227)
path traversal in path-traversal (CVE-2026-36227). Risk of unauthorized operations or information disclosure.
CVE-2025-45145 Path Traversal in path-traversal (CVE-2025-45145)
path traversal in path-traversal (CVE-2025-45145). Confidential information can be exposed externally.
CVE-2026-48777 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /public/api/resources`. Mitigation: upgrade to `0.0.0-20260518193514-28e9b81e438e` or later.
CVE-2026-34909 KEV [KEV] Path Traversal in Ubiquiti path-traversal (CVE-2026-34909)
path traversal in Ubiquiti path-traversal (CVE-2026-34909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-34911 Path Traversal in path-traversal (CVE-2026-34911)
path traversal in path-traversal (CVE-2026-34911). Confidential information can be exposed externally.
CVE-2026-8134 Vulnerability in concrete5/concrete5 (CVE-2026-8134)
vulnerability in concrete5/concrete5 (CVE-2026-8134). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
CVE-2026-46486 Path Traversal in mvt (CVE-2026-46486)
path traversal in mvt (CVE-2026-46486). Risk of unauthorized operations or information disclosure. Exploitable via ``fileID``. Mitigation: upgrade to `2026.5.12` or later.
CVE-2026-34926 KEV [KEV] Vulnerability in Trend micro path-traversal (CVE-2026-34926)
vulnerability in Trend micro path-traversal (CVE-2026-34926). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-4858 Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-4858)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-4858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.15` or later.
CVE-2026-44068 Path Traversal in path-traversal (CVE-2026-44068)
path traversal in path-traversal (CVE-2026-44068). Data can be tampered with by attackers.
CVE-2026-9129 Path Traversal in path-traversal (CVE-2026-9129)
path traversal in path-traversal (CVE-2026-9129). Risk of unauthorized operations or information disclosure.
CVE-2026-9102 Path Traversal in path-traversal (CVE-2026-9102)
path traversal in path-traversal (CVE-2026-9102). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →