Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: path-traversal Clear
ID Title
CVE-2026-39352 Path Traversal in path-traversal (CVE-2026-39352)
path traversal in path-traversal (CVE-2026-39352). Risk of unauthorized operations or information disclosure.
CVE-2026-23734 Vulnerability in org.xwiki.commons:xwiki-commons-classloader-api (CVE-2026-23734)
vulnerability in org.xwiki.commons:xwiki-commons-classloader-api (CVE-2026-23734). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.0.0-rc-1` or later.
CVE-2026-24217 Vulnerability in path-traversal (CVE-2026-24217)
vulnerability in path-traversal (CVE-2026-24217). Successful exploitation can lead to full system takeover.
CVE-2026-24208 Path Traversal in path-traversal (CVE-2026-24208)
path traversal in path-traversal (CVE-2026-24208). Risk of unauthorized operations or information disclosure.
CVE-2026-24209 Path Traversal in path-traversal (CVE-2026-24209)
path traversal in path-traversal (CVE-2026-24209). Risk of unauthorized operations or information disclosure.
CVE-2026-36829 Path Traversal in path-traversal (CVE-2026-36829)
path traversal in path-traversal (CVE-2026-36829). Successful exploitation can lead to full system takeover.
CVE-2025-70950 Path Traversal in github.com/itang/gohttp (CVE-2025-70950)
path traversal in github.com/itang/gohttp (CVE-2025-70950). Risk of unauthorized operations or information disclosure.
CVE-2026-46724 Path Traversal in tpwd/ke_search (CVE-2026-46724)
path traversal in tpwd/ke_search (CVE-2026-46724). Risk of unauthorized operations or information disclosure. Exploitable via ``ke_search``. Mitigation: upgrade to `4.6.7` or later.
CVE-2026-31379 Path Traversal in apache (CVE-2026-31379)
path traversal in apache (CVE-2026-31379). Risk of unauthorized operations or information disclosure.
CVE-2026-29220 Path Traversal in apache (CVE-2026-29220)
path traversal in apache (CVE-2026-29220). Risk of unauthorized operations or information disclosure.
CVE-2026-27891 FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the f...
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leadin...
CVE-2026-47091 Path Traversal in path-traversal (CVE-2026-47091)
path traversal in path-traversal (CVE-2026-47091). Risk of unauthorized operations or information disclosure.
CVE-2026-45242 Vulnerability in @steipete/summarize (CVE-2026-45242)
vulnerability in @steipete/summarize (CVE-2026-45242). Data can be tampered with by attackers. Mitigation: upgrade to `0.15.0` or later.
CVE-2026-29962 Vulnerability in path-traversal (CVE-2026-29962)
vulnerability in path-traversal (CVE-2026-29962). Confidential information can be exposed externally.
CVE-2026-29963 Path Traversal in path-traversal (CVE-2026-29963)
path traversal in path-traversal (CVE-2026-29963). Confidential information can be exposed externally.
CVE-2026-45230 Path Traversal in path-traversal (CVE-2026-45230)
path traversal in path-traversal (CVE-2026-45230). Data can be tampered with by attackers. Exploitable via `POST /api/delete-file`.
CVE-2026-45727 Path Traversal in cloakbrowser (CVE-2026-45727)
path traversal in cloakbrowser (CVE-2026-45727). Risk of unauthorized operations or information disclosure. Exploitable via ``cloakserve``. Mitigation: upgrade to `0.3.28` or later.
CVE-2026-41948 Vulnerability in path-traversal (CVE-2026-41948)
vulnerability in path-traversal (CVE-2026-41948). Confidential information can be exposed externally.
CVE-2026-7302 Vulnerability in sglang (CVE-2026-7302)
vulnerability in sglang (CVE-2026-7302). Data can be tampered with by attackers.
CVE-2026-8802 Path Traversal in path-traversal (CVE-2026-8802)
path traversal in path-traversal (CVE-2026-8802). Risk of unauthorized operations or information disclosure.
CVE-2026-8770 Path Traversal in path-traversal (CVE-2026-8770)
path traversal in path-traversal (CVE-2026-8770). Risk of unauthorized operations or information disclosure.
CVE-2026-8765 Path Traversal in path-traversal (CVE-2026-8765)
path traversal in path-traversal (CVE-2026-8765). Risk of unauthorized operations or information disclosure.
CVE-2026-8757 Path Traversal in path-traversal (CVE-2026-8757)
path traversal in path-traversal (CVE-2026-8757). Risk of unauthorized operations or information disclosure.
CVE-2026-8754 Path Traversal in AstrBot (CVE-2026-8754)
path traversal in AstrBot (CVE-2026-8754). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.23.6` or later.
CVE-2026-8755 Path Traversal in path-traversal (CVE-2026-8755)
path traversal in path-traversal (CVE-2026-8755). Risk of unauthorized operations or information disclosure.
CVE-2026-8756 Path Traversal in path-traversal (CVE-2026-8756)
path traversal in path-traversal (CVE-2026-8756). Risk of unauthorized operations or information disclosure.
CVE-2018-25326 Path Traversal in wordpress (CVE-2018-25326)
path traversal in wordpress (CVE-2018-25326). Confidential information can be exposed externally.
CVE-2018-25325 Path Traversal in wordpress (CVE-2018-25325)
path traversal in wordpress (CVE-2018-25325). Confidential information can be exposed externally.
CVE-2026-8736 Path Traversal in path-traversal (CVE-2026-8736)
path traversal in path-traversal (CVE-2026-8736). Risk of unauthorized operations or information disclosure.
CVE-2021-47977 Path Traversal in wordpress (CVE-2021-47977)
path traversal in wordpress (CVE-2021-47977). Confidential information can be exposed externally.
CVE-2021-47978 Vulnerability in path-traversal (CVE-2021-47978)
vulnerability in path-traversal (CVE-2021-47978). Confidential information can be exposed externally.
CVE-2021-47942 Path Traversal in path-traversal (CVE-2021-47942)
path traversal in path-traversal (CVE-2021-47942). Confidential information can be exposed externally.
CVE-2020-37245 Cross-Site Scripting (XSS) in path-traversal (CVE-2020-37245)
cross-site scripting in path-traversal (CVE-2020-37245). Confidential information can be exposed externally.
CVE-2020-37246 Vulnerability in path-traversal (CVE-2020-37246)
vulnerability in path-traversal (CVE-2020-37246). Confidential information can be exposed externally.
CVE-2026-45008 Path Traversal in phpMyFAQ/phpMyFAQ (CVE-2026-45008)
path traversal in phpMyFAQ/phpMyFAQ (CVE-2026-45008). Data can be tampered with by attackers. Exploitable via ``clientFolder``. Mitigation: upgrade to `4.1.2` or later.
CVE-2026-46491 Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
path traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491). Data can be tampered with by attackers. Exploitable via ``ticket``. Mitigation: upgrade to `7.0.3` or later.
CVE-2026-44716 Path Traversal in pipecat-ai (CVE-2026-44716)
path traversal in pipecat-ai (CVE-2026-44716). Confidential information can be exposed externally. Exploitable via `GET /files/{filename`. Mitigation: upgrade to `1.2.0` or later.
CVE-2026-22810 Vulnerability in @joplin/onenote-converter (CVE-2026-22810)
vulnerability in @joplin/onenote-converter (CVE-2026-22810). Successful exploitation can lead to full system takeover. Exploitable via ``embedded_file.rs``. Mitigation: upgrade to `3.5.7` or later.
CVE-2026-7182 Path Traversal in path-traversal (CVE-2026-7182)
path traversal in path-traversal (CVE-2026-7182). Risk of unauthorized operations or information disclosure.
CVE-2026-41552 Path Traversal in path-traversal (CVE-2026-41552)
path traversal in path-traversal (CVE-2026-41552). Confidential information can be exposed externally.
CVE-2026-6403 Path Traversal in wordpress (CVE-2026-6403)
path traversal in wordpress (CVE-2026-6403). Confidential information can be exposed externally.
CVE-2026-44522 Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/notes/{noteID}/assets`. Mitigation: upgrade to `0.0.0-20260501152243-db3f72bff780` or later.
CVE-2026-44973 Path Traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973)
path traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973). Confidential information can be exposed externally. Exploitable via ``osfs.ChrootOS``. Mitigation: upgrade to `5.9.0` or later.
CVE-2026-44885 Path Traversal in github.com/portainer/portainer (CVE-2026-44885)
path traversal in github.com/portainer/portainer (CVE-2026-44885). Data can be tampered with by attackers. Exploitable via ``ExtractTarGz``. Mitigation: upgrade to `2.33.8` or later.
CVE-2026-6670 Path Traversal in wordpress (CVE-2026-6670)
path traversal in wordpress (CVE-2026-6670). Confidential information can be exposed externally.
CVE-2026-44440 Path Traversal in path-traversal (CVE-2026-44440)
path traversal in path-traversal (CVE-2026-44440). Confidential information can be exposed externally. Mitigation: upgrade to `15.101.1` or later.
CVE-2026-44437 Path Traversal in @angular/ssr (CVE-2026-44437)
path traversal in @angular/ssr (CVE-2026-44437). Risk of unauthorized operations or information disclosure. Exploitable via ``redirectTo``. Mitigation: upgrade to `19.2.25` or later.
CVE-2026-44373 Path Traversal in nitro (CVE-2026-44373)
path traversal in nitro (CVE-2026-44373). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/orders/..`. Mitigation: upgrade to `3.0.260429-beta` or later.
CVE-2026-42552 Vulnerability in flightphp/core (CVE-2026-42552)
vulnerability in flightphp/core (CVE-2026-42552). Confidential information can be exposed externally. Exploitable via ``flight.debug``. Mitigation: upgrade to `3.18.1` or later.
CVE-2026-22677 Path Traversal in path-traversal (CVE-2026-22677)
path traversal in path-traversal (CVE-2026-22677). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →