Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-35031 |
|
Vulnerability in path-traversal (CVE-2026-35031)
vulnerability in path-traversal (CVE-2026-35031). Successful exploitation can lead to full system takeover. Exploitable via `POST /Videos/{itemId}/Subtitles`.
|
| CVE-2026-34619 |
|
Path Traversal in path-traversal (CVE-2026-34619)
path traversal in path-traversal (CVE-2026-34619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27305 |
|
Path Traversal in path-traversal (CVE-2026-27305)
path traversal in path-traversal (CVE-2026-27305). Confidential information can be exposed externally.
|
| CVE-2026-39813 |
|
Vulnerability in path-traversal (CVE-2026-39813)
vulnerability in path-traversal (CVE-2026-39813). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61624 |
|
Path Traversal in path-traversal (CVE-2025-61624)
path traversal in path-traversal (CVE-2025-61624). Data can be tampered with by attackers.
|
| CVE-2026-32146 |
|
Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
|
| CVE-2026-6057 |
|
Path Traversal in path-traversal (CVE-2026-6057)
path traversal in path-traversal (CVE-2026-6057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39981 |
|
Path Traversal in path-traversal (CVE-2026-39981)
path traversal in path-traversal (CVE-2026-39981). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-40027 |
|
Path Traversal in path-traversal (CVE-2026-40027)
path traversal in path-traversal (CVE-2026-40027). Confidential information can be exposed externally.
|
| CVE-2026-40024 |
|
Path Traversal in path-traversal (CVE-2026-40024)
path traversal in path-traversal (CVE-2026-40024). Confidential information can be exposed externally.
|
| CVE-2026-33466 |
|
Path Traversal in path-traversal (CVE-2026-33466)
path traversal in path-traversal (CVE-2026-33466). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39408 |
|
Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-39847 |
|
Path Traversal in emmett (CVE-2026-39847)
path traversal in emmett (CVE-2026-39847). Confidential information can be exposed externally. Mitigation: upgrade to `2.8.1` or later.
|
| CVE-2026-35454 |
|
Path Traversal in github.com/coder/code-marketplace (CVE-2026-35454)
path traversal in github.com/coder/code-marketplace (CVE-2026-35454). Data can be tampered with by attackers. Exploitable via ``ExtractZip``. Mitigation: upgrade to `1.2.3-0.20260402184705-988440dee05f` or later.
|
| CVE-2026-35471 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35177 |
|
Path Traversal in c (CVE-2026-35177)
path traversal in c (CVE-2026-35177). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0280` or later.
|
| CVE-2026-35174 |
|
Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
|
| CVE-2026-5597 |
|
Path Traversal in path-traversal (CVE-2026-5597)
path traversal in path-traversal (CVE-2026-5597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5595 |
|
Path Traversal in path-traversal (CVE-2026-5595)
path traversal in path-traversal (CVE-2026-5595). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5535 |
|
Path Traversal in path-traversal (CVE-2026-5535)
path traversal in path-traversal (CVE-2026-5535). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3666 |
|
Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34607 |
|
Path Traversal in path-traversal (CVE-2026-34607)
path traversal in path-traversal (CVE-2026-34607). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34978 |
|
Path Traversal in path-traversal (CVE-2026-34978)
path traversal in path-traversal (CVE-2026-34978). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26058 |
|
Path Traversal in path-traversal (CVE-2026-26058)
path traversal in path-traversal (CVE-2026-26058). Confidential information can be exposed externally.
|
| CVE-2026-22661 |
|
Path Traversal in path-traversal (CVE-2026-22661)
path traversal in path-traversal (CVE-2026-22661). Confidential information can be exposed externally.
|
| CVE-2026-28373 |
|
Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35214 |
|
Path Traversal in path-traversal (CVE-2026-35214)
path traversal in path-traversal (CVE-2026-35214). Data can be tampered with by attackers. Exploitable via `POST /api/plugin/upload`.
|
| CVE-2025-59711 |
|
Path Traversal in path-traversal (CVE-2025-59711)
path traversal in path-traversal (CVE-2025-59711). Confidential information can be exposed externally.
|
| CVE-2025-59709 |
|
Path Traversal in c (CVE-2025-59709)
path traversal in c (CVE-2025-59709). Confidential information can be exposed externally.
|
| CVE-2026-4350 |
|
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
|
| CVE-2026-34726 |
|
Path Traversal in path-traversal (CVE-2026-34726)
path traversal in path-traversal (CVE-2026-34726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34522 |
|
Path Traversal in path-traversal (CVE-2026-34522)
path traversal in path-traversal (CVE-2026-34522). Data can be tampered with by attackers.
|
| CVE-2026-34523 |
|
Path Traversal in path-traversal (CVE-2026-34523)
path traversal in path-traversal (CVE-2026-34523). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34524 |
|
Path Traversal in path-traversal (CVE-2026-34524)
path traversal in path-traversal (CVE-2026-34524). Confidential information can be exposed externally.
|
| CVE-2026-5344 |
|
Path Traversal in path-traversal (CVE-2026-5344)
path traversal in path-traversal (CVE-2026-5344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32871 |
|
SSRF (Server-Side Request Forgery) in fastmcp (CVE-2026-32871)
SSRF in fastmcp (CVE-2026-32871). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-3987 |
|
Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27489 |
|
Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
|
| CVE-2026-41363 |
|
Path Traversal in openclaw (CVE-2026-41363)
path traversal in openclaw (CVE-2026-41363). Confidential information can be exposed externally. Mitigation: upgrade to `>= 2026.3.28` or later.
|
| CVE-2026-32725 |
|
Vulnerability in c (CVE-2026-32725)
vulnerability in c (CVE-2026-32725). Confidential information can be exposed externally.
|
| CVE-2026-5203 |
|
Path Traversal in path-traversal (CVE-2026-5203)
path traversal in path-traversal (CVE-2026-5203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29870 |
|
Path Traversal in path-traversal (CVE-2026-29870)
path traversal in path-traversal (CVE-2026-29870). Data can be tampered with by attackers.
|
| CVE-2026-34070 |
|
Path Traversal in path-traversal (CVE-2026-34070)
path traversal in path-traversal (CVE-2026-34070). Confidential information can be exposed externally.
|
| CVE-2025-15036 |
|
Vulnerability in mlflow (CVE-2025-15036)
vulnerability in mlflow (CVE-2025-15036). Successful exploitation can lead to full system takeover. Exploitable via ``extract_archive_to_dir``. Mitigation: upgrade to `3.9.0rc0` or later.
|
| CVE-2026-5027 |
|
Path Traversal in path-traversal (CVE-2026-5027)
path traversal in path-traversal (CVE-2026-5027). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/files`.
|
| CVE-2026-32846 |
|
Path Traversal in openclaw (CVE-2026-32846)
path traversal in openclaw (CVE-2026-32846). Confidential information can be exposed externally. Mitigation: upgrade to `2026.03.28` or later.
|
| CVE-2025-67030 |
|
Path Traversal in path-traversal (CVE-2025-67030)
path traversal in path-traversal (CVE-2025-67030). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33211 |
|
Path Traversal in path-traversal (CVE-2026-33211)
path traversal in path-traversal (CVE-2026-33211). Confidential information can be exposed externally. Exploitable via ``pathInRepo``.
|
| CVE-2026-33195 |
|
Path Traversal in activestorage (CVE-2026-33195)
path traversal in activestorage (CVE-2026-33195). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.3.1` or later.
|
| CVE-2026-33236 |
|
Path Traversal in path-traversal (CVE-2026-33236)
path traversal in path-traversal (CVE-2026-33236). Data can be tampered with by attackers. Exploitable via ``subdir``.
|