Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-22 Clear
ID Title
CVE-2026-46402 Path Traversal in path-traversal (CVE-2026-46402)
path traversal in path-traversal (CVE-2026-46402). Data can be tampered with by attackers.
CVE-2026-47243 Path Traversal in github.com/kata-containers/kata-containers (CVE-2026-47243)
path traversal in github.com/kata-containers/kata-containers (CVE-2026-47243). Risk of unauthorized operations or information disclosure. Exploitable via ``virtiofsd``. Mitigation: upgrade to `0.0.0-20260519062212-ffa59ce3aa78` or later.
CVE-2026-45309 Path Traversal in asyncssh (CVE-2026-45309)
path traversal in asyncssh (CVE-2026-45309). Data can be tampered with by attackers. Exploitable via ``AuthorizedKeysFile``. Mitigation: upgrade to `2.23.0` or later.
CVE-2026-49009 Path Traversal in path-traversal (CVE-2026-49009)
path traversal in path-traversal (CVE-2026-49009). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-3366 Path Traversal in ibm (CVE-2026-3366)
path traversal in ibm (CVE-2026-3366). Confidential information can be exposed externally.
CVE-2026-6957 Path Traversal in mattermost (CVE-2026-6957)
path traversal in mattermost (CVE-2026-6957). Successful exploitation can lead to full system takeover.
CVE-2026-47118 Path Traversal in path-traversal (CVE-2026-47118)
path traversal in path-traversal (CVE-2026-47118). Confidential information can be exposed externally.
CVE-2026-48544 Path Traversal in taipy (CVE-2026-48544)
path traversal in taipy (CVE-2026-48544). Confidential information can be exposed externally.
CVE-2026-9035 Path Traversal in ibm (CVE-2026-9035)
path traversal in ibm (CVE-2026-9035). Confidential information can be exposed externally.
CVE-2026-7524 Path Traversal in langflow (CVE-2026-7524)
path traversal in langflow (CVE-2026-7524). Successful exploitation can lead to full system takeover.
CVE-2026-42756 Path Traversal in path-traversal (CVE-2026-42756)
path traversal in path-traversal (CVE-2026-42756). Successful exploitation can lead to full system takeover.
CVE-2026-42757 Path Traversal in path-traversal (CVE-2026-42757)
path traversal in path-traversal (CVE-2026-42757). Successful exploitation can lead to full system takeover.
CVE-2026-42737 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
CVE-2026-41009 Path Traversal in cloud-foundry (CVE-2026-41009)
path traversal in cloud-foundry (CVE-2026-41009). Data can be tampered with by attackers.
CVE-2024-47267 Path Traversal in path-traversal (CVE-2024-47267)
path traversal in path-traversal (CVE-2024-47267). Risk of unauthorized operations or information disclosure.
CVE-2026-44705 Path Traversal in tmp (CVE-2026-44705)
path traversal in tmp (CVE-2026-44705). Data can be tampered with by attackers. Exploitable via ``prefix``. Mitigation: upgrade to `0.2.6` or later.
CVE-2026-44177 Path Traversal in getkirby/cms (CVE-2026-44177)
path traversal in getkirby/cms (CVE-2026-44177). Risk of unauthorized operations or information disclosure. Exploitable via ``Users``. Mitigation: upgrade to `5.4.1` or later.
CVE-2026-42448 Path Traversal in magic-wormhole (CVE-2026-42448)
path traversal in magic-wormhole (CVE-2026-42448). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.24.0` or later.
CVE-2026-48126 Path Traversal in github.com/xyproto/algernon (CVE-2026-48126)
path traversal in github.com/xyproto/algernon (CVE-2026-48126). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `1.17.8` or later.
CVE-2026-43982 Path Traversal in CVE-2026-43982 (CVE-2026-43982)
path traversal in CVE-2026-43982 (CVE-2026-43982). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.17.6` or later.
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
CVE-2026-40384 Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-9550 Path Traversal in path-traversal (CVE-2026-9550)
path traversal in path-traversal (CVE-2026-9550). Risk of unauthorized operations or information disclosure.
CVE-2026-41917 Path Traversal in CVE-2026-41917 (CVE-2026-41917)
path traversal in CVE-2026-41917 (CVE-2026-41917). Confidential information can be exposed externally.
CVE-2026-42496 Vulnerability in archive (CVE-2026-42496)
vulnerability in archive (CVE-2026-42496). Confidential information can be exposed externally.
CVE-2026-9472 Path Traversal in path-traversal (CVE-2026-9472)
path traversal in path-traversal (CVE-2026-9472). Risk of unauthorized operations or information disclosure.
CVE-2026-9473 Path Traversal in c (CVE-2026-9473)
path traversal in c (CVE-2026-9473). Risk of unauthorized operations or information disclosure.
CVE-2026-9467 Path Traversal in path-traversal (CVE-2026-9467)
path traversal in path-traversal (CVE-2026-9467). Risk of unauthorized operations or information disclosure.
CVE-2026-9468 Path Traversal in path-traversal (CVE-2026-9468)
path traversal in path-traversal (CVE-2026-9468). Risk of unauthorized operations or information disclosure.
CVE-2018-25374 Path Traversal in c (CVE-2018-25374)
path traversal in c (CVE-2018-25374). Confidential information can be exposed externally.
CVE-2018-25365 Path Traversal in path-traversal (CVE-2018-25365)
path traversal in path-traversal (CVE-2018-25365). Confidential information can be exposed externally.
CVE-2026-7766 Path Traversal in path-traversal (CVE-2026-7766)
path traversal in path-traversal (CVE-2026-7766). Risk of unauthorized operations or information disclosure.
CVE-2026-41863 Path Traversal in org.springframework.ai:spring-ai-anthropic (CVE-2026-41863)
path traversal in org.springframework.ai:spring-ai-anthropic (CVE-2026-41863). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.7` or later.
CVE-2026-9489 Path Traversal in privilege-escalation (CVE-2026-9489)
path traversal in privilege-escalation (CVE-2026-9489). Risk of unauthorized operations or information disclosure.
CVE-2026-9351 Path Traversal in path-traversal (CVE-2026-9351)
path traversal in path-traversal (CVE-2026-9351). Risk of unauthorized operations or information disclosure.
CVE-2026-36227 Path Traversal in path-traversal (CVE-2026-36227)
path traversal in path-traversal (CVE-2026-36227). Risk of unauthorized operations or information disclosure.
CVE-2025-45145 Path Traversal in path-traversal (CVE-2025-45145)
path traversal in path-traversal (CVE-2025-45145). Confidential information can be exposed externally.
CVE-2026-45390 Path Traversal in tar (CVE-2026-45390)
path traversal in tar (CVE-2026-45390). Confidential information can be exposed externally. Mitigation: upgrade to `3.5.0, 51ceb0a15982993503c169b9d84456fd50eabe99` or later.
CVE-2026-48777 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /public/api/resources`. Mitigation: upgrade to `0.0.0-20260518193514-28e9b81e438e` or later.
CVE-2026-34909 KEV [KEV] Path Traversal in Ubiquiti path-traversal (CVE-2026-34909)
path traversal in Ubiquiti path-traversal (CVE-2026-34909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-34911 Path Traversal in path-traversal (CVE-2026-34911)
path traversal in path-traversal (CVE-2026-34911). Confidential information can be exposed externally.
CVE-2026-46671 Path Traversal in onenote_parser (CVE-2026-46671)
path traversal in onenote_parser (CVE-2026-46671). Risk of unauthorized operations or information disclosure. Exploitable via ``onenote_parser``. Mitigation: upgrade to `1.1.1` or later.
CVE-2026-46486 Path Traversal in mvt (CVE-2026-46486)
path traversal in mvt (CVE-2026-46486). Risk of unauthorized operations or information disclosure. Exploitable via ``fileID``. Mitigation: upgrade to `2026.5.12` or later.
CVE-2025-71210 Path Traversal in trendmicro (CVE-2025-71210)
path traversal in trendmicro (CVE-2025-71210). Successful exploitation can lead to full system takeover.
CVE-2025-71211 Path Traversal in trendmicro (CVE-2025-71211)
path traversal in trendmicro (CVE-2025-71211). Successful exploitation can lead to full system takeover.
CVE-2026-4858 Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-4858)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-4858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.15` or later.
CVE-2026-44068 Path Traversal in path-traversal (CVE-2026-44068)
path traversal in path-traversal (CVE-2026-44068). Data can be tampered with by attackers.
CVE-2026-9129 Path Traversal in path-traversal (CVE-2026-9129)
path traversal in path-traversal (CVE-2026-9129). Risk of unauthorized operations or information disclosure.
CVE-2026-9102 Path Traversal in path-traversal (CVE-2026-9102)
path traversal in path-traversal (CVE-2026-9102). Risk of unauthorized operations or information disclosure.
CVE-2026-39352 Path Traversal in path-traversal (CVE-2026-39352)
path traversal in path-traversal (CVE-2026-39352). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →