Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: path-traversal Clear
ID Title
CVE-2026-35031 Vulnerability in path-traversal (CVE-2026-35031)
vulnerability in path-traversal (CVE-2026-35031). Successful exploitation can lead to full system takeover. Exploitable via `POST /Videos/{itemId}/Subtitles`.
CVE-2026-34619 Path Traversal in path-traversal (CVE-2026-34619)
path traversal in path-traversal (CVE-2026-34619). Risk of unauthorized operations or information disclosure.
CVE-2026-27305 Path Traversal in path-traversal (CVE-2026-27305)
path traversal in path-traversal (CVE-2026-27305). Confidential information can be exposed externally.
CVE-2026-39813 Vulnerability in path-traversal (CVE-2026-39813)
vulnerability in path-traversal (CVE-2026-39813). Successful exploitation can lead to full system takeover.
CVE-2025-61624 Path Traversal in path-traversal (CVE-2025-61624)
path traversal in path-traversal (CVE-2025-61624). Data can be tampered with by attackers.
CVE-2026-32146 Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
CVE-2026-6057 Path Traversal in path-traversal (CVE-2026-6057)
path traversal in path-traversal (CVE-2026-6057). Successful exploitation can lead to full system takeover.
CVE-2026-39981 Path Traversal in path-traversal (CVE-2026-39981)
path traversal in path-traversal (CVE-2026-39981). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.9.2` or later.
CVE-2026-40027 Path Traversal in path-traversal (CVE-2026-40027)
path traversal in path-traversal (CVE-2026-40027). Confidential information can be exposed externally.
CVE-2026-40024 Path Traversal in path-traversal (CVE-2026-40024)
path traversal in path-traversal (CVE-2026-40024). Confidential information can be exposed externally.
CVE-2026-33466 Path Traversal in path-traversal (CVE-2026-33466)
path traversal in path-traversal (CVE-2026-33466). Successful exploitation can lead to full system takeover.
CVE-2026-39408 Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
CVE-2026-39847 Path Traversal in emmett (CVE-2026-39847)
path traversal in emmett (CVE-2026-39847). Confidential information can be exposed externally. Mitigation: upgrade to `2.8.1` or later.
CVE-2026-35454 Path Traversal in github.com/coder/code-marketplace (CVE-2026-35454)
path traversal in github.com/coder/code-marketplace (CVE-2026-35454). Data can be tampered with by attackers. Exploitable via ``ExtractZip``. Mitigation: upgrade to `1.2.3-0.20260402184705-988440dee05f` or later.
CVE-2026-35471 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35177 Path Traversal in c (CVE-2026-35177)
path traversal in c (CVE-2026-35177). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0280` or later.
CVE-2026-35174 Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
CVE-2026-5597 Path Traversal in path-traversal (CVE-2026-5597)
path traversal in path-traversal (CVE-2026-5597). Risk of unauthorized operations or information disclosure.
CVE-2026-5595 Path Traversal in path-traversal (CVE-2026-5595)
path traversal in path-traversal (CVE-2026-5595). Risk of unauthorized operations or information disclosure.
CVE-2026-5535 Path Traversal in path-traversal (CVE-2026-5535)
path traversal in path-traversal (CVE-2026-5535). Risk of unauthorized operations or information disclosure.
CVE-2026-3666 Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
CVE-2026-34607 Path Traversal in path-traversal (CVE-2026-34607)
path traversal in path-traversal (CVE-2026-34607). Successful exploitation can lead to full system takeover.
CVE-2026-34978 Path Traversal in path-traversal (CVE-2026-34978)
path traversal in path-traversal (CVE-2026-34978). Risk of unauthorized operations or information disclosure.
CVE-2026-26058 Path Traversal in path-traversal (CVE-2026-26058)
path traversal in path-traversal (CVE-2026-26058). Confidential information can be exposed externally.
CVE-2026-22661 Path Traversal in path-traversal (CVE-2026-22661)
path traversal in path-traversal (CVE-2026-22661). Confidential information can be exposed externally.
CVE-2026-28373 Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
CVE-2026-35214 Path Traversal in path-traversal (CVE-2026-35214)
path traversal in path-traversal (CVE-2026-35214). Data can be tampered with by attackers. Exploitable via `POST /api/plugin/upload`.
CVE-2025-59711 Path Traversal in path-traversal (CVE-2025-59711)
path traversal in path-traversal (CVE-2025-59711). Confidential information can be exposed externally.
CVE-2025-59709 Path Traversal in c (CVE-2025-59709)
path traversal in c (CVE-2025-59709). Confidential information can be exposed externally.
CVE-2026-4350 The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
CVE-2026-34726 Path Traversal in path-traversal (CVE-2026-34726)
path traversal in path-traversal (CVE-2026-34726). Risk of unauthorized operations or information disclosure.
CVE-2026-34522 Path Traversal in path-traversal (CVE-2026-34522)
path traversal in path-traversal (CVE-2026-34522). Data can be tampered with by attackers.
CVE-2026-34523 Path Traversal in path-traversal (CVE-2026-34523)
path traversal in path-traversal (CVE-2026-34523). Risk of unauthorized operations or information disclosure.
CVE-2026-34524 Path Traversal in path-traversal (CVE-2026-34524)
path traversal in path-traversal (CVE-2026-34524). Confidential information can be exposed externally.
CVE-2026-5344 Path Traversal in path-traversal (CVE-2026-5344)
path traversal in path-traversal (CVE-2026-5344). Risk of unauthorized operations or information disclosure.
CVE-2026-32871 SSRF (Server-Side Request Forgery) in fastmcp (CVE-2026-32871)
SSRF in fastmcp (CVE-2026-32871). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.2.0` or later.
CVE-2026-3987 Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
CVE-2026-27489 Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
CVE-2026-41363 Path Traversal in openclaw (CVE-2026-41363)
path traversal in openclaw (CVE-2026-41363). Confidential information can be exposed externally. Mitigation: upgrade to `>= 2026.3.28` or later.
CVE-2026-32725 Vulnerability in c (CVE-2026-32725)
vulnerability in c (CVE-2026-32725). Confidential information can be exposed externally.
CVE-2026-5203 Path Traversal in path-traversal (CVE-2026-5203)
path traversal in path-traversal (CVE-2026-5203). Risk of unauthorized operations or information disclosure.
CVE-2026-29870 Path Traversal in path-traversal (CVE-2026-29870)
path traversal in path-traversal (CVE-2026-29870). Data can be tampered with by attackers.
CVE-2026-34070 Path Traversal in path-traversal (CVE-2026-34070)
path traversal in path-traversal (CVE-2026-34070). Confidential information can be exposed externally.
CVE-2025-15036 Vulnerability in mlflow (CVE-2025-15036)
vulnerability in mlflow (CVE-2025-15036). Successful exploitation can lead to full system takeover. Exploitable via ``extract_archive_to_dir``. Mitigation: upgrade to `3.9.0rc0` or later.
CVE-2026-5027 Path Traversal in path-traversal (CVE-2026-5027)
path traversal in path-traversal (CVE-2026-5027). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/files`.
CVE-2026-32846 Path Traversal in openclaw (CVE-2026-32846)
path traversal in openclaw (CVE-2026-32846). Confidential information can be exposed externally. Mitigation: upgrade to `2026.03.28` or later.
CVE-2025-67030 Path Traversal in path-traversal (CVE-2025-67030)
path traversal in path-traversal (CVE-2025-67030). Successful exploitation can lead to full system takeover.
CVE-2026-33211 Path Traversal in path-traversal (CVE-2026-33211)
path traversal in path-traversal (CVE-2026-33211). Confidential information can be exposed externally. Exploitable via ``pathInRepo``.
CVE-2026-33195 Path Traversal in activestorage (CVE-2026-33195)
path traversal in activestorage (CVE-2026-33195). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.3.1` or later.
CVE-2026-33236 Path Traversal in path-traversal (CVE-2026-33236)
path traversal in path-traversal (CVE-2026-33236). Data can be tampered with by attackers. Exploitable via ``subdir``.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →