Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19285 |
|
Path Traversal in path-traversal (CVE-2026-19285)
path traversal in path-traversal (CVE-2026-19285). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19270 |
|
Path Traversal in path-traversal (CVE-2026-19270)
path traversal in path-traversal (CVE-2026-19270). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16955 |
|
Path Traversal in wordpress (CVE-2026-16955)
path traversal in wordpress (CVE-2026-16955). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19016 |
|
Path Traversal in CVE-2026-19016 (CVE-2026-19016)
path traversal in CVE-2026-19016 (CVE-2026-19016). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50540 |
|
Vulnerability in CVE-2026-50540 (CVE-2026-50540)
vulnerability in CVE-2026-50540 (CVE-2026-50540). Confidential information can be exposed externally.
|
| CVE-2026-47661 |
|
Path Traversal in path-traversal (CVE-2026-47661)
path traversal in path-traversal (CVE-2026-47661). Risk of unauthorized operations or information disclosure. Exploitable via ``file``.
|
| CVE-2026-47659 |
|
Path Traversal in path-traversal (CVE-2026-47659)
path traversal in path-traversal (CVE-2026-47659). Risk of unauthorized operations or information disclosure. Exploitable via ``file``.
|
| CVE-2026-71557 |
|
Path Traversal in github.com/go-git/go-git/v5 (CVE-2026-71557)
path traversal in github.com/go-git/go-git/v5 (CVE-2026-71557). Data can be tampered with by attackers. Exploitable via ``dotgit``. Mitigation: upgrade to `5.19.2` or later.
|
| CVE-2026-66914 |
|
Path Traversal in path-traversal (CVE-2026-66914)
path traversal in path-traversal (CVE-2026-66914). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19264 |
|
Path Traversal in CVE-2026-19264 (CVE-2026-19264)
path traversal in CVE-2026-19264 (CVE-2026-19264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62996 |
|
Path Traversal in smarty/smarty (CVE-2026-62996)
path traversal in smarty/smarty (CVE-2026-62996). Risk of unauthorized operations or information disclosure. Exploitable via ``stream``. Mitigation: upgrade to `5.8.4` or later.
|
| CVE-2026-62992 |
|
Path Traversal in smarty/smarty (CVE-2026-62992)
path traversal in smarty/smarty (CVE-2026-62992). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.8.2` or later.
|
| CVE-2026-66492 |
|
Path Traversal in path-traversal (CVE-2026-66492)
path traversal in path-traversal (CVE-2026-66492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66491 |
|
Path Traversal in CVE-2026-66491 (CVE-2026-66491)
path traversal in CVE-2026-66491 (CVE-2026-66491). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66493 |
|
Path Traversal in path-traversal (CVE-2026-66493)
path traversal in path-traversal (CVE-2026-66493). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16263 |
|
Path Traversal in wordpress (CVE-2026-16263)
path traversal in wordpress (CVE-2026-16263). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49163 |
|
Path Traversal in path-traversal (CVE-2026-49163)
path traversal in path-traversal (CVE-2026-49163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64677 |
|
Path Traversal in path-traversal (CVE-2026-64677)
path traversal in path-traversal (CVE-2026-64677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64653 |
|
Path Traversal in CVE-2026-64653 (CVE-2026-64653)
path traversal in CVE-2026-64653 (CVE-2026-64653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41861 |
|
Path Traversal in path-traversal (CVE-2026-41861)
path traversal in path-traversal (CVE-2026-41861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19054 |
|
Path Traversal in path-traversal (CVE-2026-19054)
path traversal in path-traversal (CVE-2026-19054). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19059 |
|
Path Traversal in path-traversal (CVE-2026-19059)
path traversal in path-traversal (CVE-2026-19059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71476 |
|
Path Traversal in nx (CVE-2026-71476)
path traversal in nx (CVE-2026-71476). Risk of unauthorized operations or information disclosure. Exploitable via ``NX_SELF_HOSTED_REMOTE_CACHE_SERVER``. Mitigation: upgrade to `23.0.2` or later.
|
| CVE-2026-19046 |
|
Path Traversal in path-traversal (CVE-2026-19046)
path traversal in path-traversal (CVE-2026-19046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18427 |
|
Path Traversal in CVE-2026-18427 (CVE-2026-18427)
path traversal in CVE-2026-18427 (CVE-2026-18427). Confidential information can be exposed externally.
|
| CVE-2026-53976 |
|
Path Traversal in path-traversal (CVE-2026-53976)
path traversal in path-traversal (CVE-2026-53976). Confidential information can be exposed externally.
|
| CVE-2026-28146 |
|
Path Traversal in CVE-2026-28146 (CVE-2026-28146)
path traversal in CVE-2026-28146 (CVE-2026-28146). Confidential information can be exposed externally.
|
| CVE-2026-19038 |
|
Path Traversal in path-traversal (CVE-2026-19038)
path traversal in path-traversal (CVE-2026-19038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18991 |
|
Path Traversal in path-traversal (CVE-2026-18991)
path traversal in path-traversal (CVE-2026-18991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18959 |
|
Path Traversal in path-traversal (CVE-2026-18959)
path traversal in path-traversal (CVE-2026-18959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71313 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-71313)
path traversal in github.com/rclone/rclone (CVE-2026-71313). Data can be tampered with by attackers. Exploitable via ``Dot``. Mitigation: upgrade to `1.75.0` or later.
|
| CVE-2026-18953 |
|
Path Traversal in Amazon aws (CVE-2026-18953)
path traversal in Amazon aws (CVE-2026-18953). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17556 |
|
Path Traversal in path-traversal (CVE-2026-17556)
path traversal in path-traversal (CVE-2026-17556). Data can be tampered with by attackers.
|
| CVE-2026-71309 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-71309)
path traversal in github.com/rclone/rclone (CVE-2026-71309). Risk of unauthorized operations or information disclosure. Exploitable via `GET /../`. Mitigation: upgrade to `1.75.0` or later.
|
| CVE-2026-8183 |
|
Path Traversal in langflow (CVE-2026-8183)
path traversal in langflow (CVE-2026-8183). Confidential information can be exposed externally.
|
| CVE-2026-7658 |
|
Path Traversal in path-traversal (CVE-2026-7658)
path traversal in path-traversal (CVE-2026-7658). Data can be tampered with by attackers.
|
| CVE-2026-7869 |
|
Path Traversal in path-traversal (CVE-2026-7869)
path traversal in path-traversal (CVE-2026-7869). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`.
|
| CVE-2026-70428 |
|
Path Traversal in path-traversal (CVE-2026-70428)
path traversal in path-traversal (CVE-2026-70428). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7646 |
|
Path Traversal in path-traversal (CVE-2026-7646)
path traversal in path-traversal (CVE-2026-7646). Confidential information can be exposed externally.
|
| CVE-2026-9195 |
|
Path Traversal in CVE-2026-9195 (CVE-2026-9195)
path traversal in CVE-2026-9195 (CVE-2026-9195). Confidential information can be exposed externally.
|
| CVE-2026-15979 |
|
Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
|
| CVE-2026-71283 |
|
Path Traversal in CVE-2026-71283 (CVE-2026-71283)
path traversal in CVE-2026-71283 (CVE-2026-71283). Data can be tampered with by attackers.
|
| CVE-2026-71279 |
|
Path Traversal in CVE-2026-71279 (CVE-2026-71279)
path traversal in CVE-2026-71279 (CVE-2026-71279). Successful exploitation can lead to full system takeover. Exploitable via ``name``.
|
| CVE-2026-71269 |
|
Path Traversal in CVE-2026-71269 (CVE-2026-71269)
path traversal in CVE-2026-71269 (CVE-2026-71269). Successful exploitation can lead to full system takeover. Exploitable via `POST /library/`.
|
| CVE-2026-71268 |
|
Path Traversal in CVE-2026-71268 (CVE-2026-71268)
path traversal in CVE-2026-71268 (CVE-2026-71268). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46581 |
|
Path Traversal in eclipse (CVE-2026-46581)
path traversal in eclipse (CVE-2026-46581). Confidential information can be exposed externally. Exploitable via ``DefaultFaceletFactory``.
|
| CVE-2026-61891 |
|
Path Traversal in eclipse (CVE-2026-61891)
path traversal in eclipse (CVE-2026-61891). Confidential information can be exposed externally. Exploitable via `GET /file`.
|
| CVE-2026-12609 |
|
Path Traversal in eclipse (CVE-2026-12609)
path traversal in eclipse (CVE-2026-12609). Confidential information can be exposed externally.
|
| CVE-2026-60009 |
|
Path Traversal in eclipse (CVE-2026-60009)
path traversal in eclipse (CVE-2026-60009). Successful exploitation can lead to full system takeover. Exploitable via `POST /file-upload`.
|
| CVE-2026-71215 |
|
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
|