Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-71215 |
|
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
|
| CVE-2026-55747 |
|
Path Traversal in CVE-2026-55747 (CVE-2026-55747)
path traversal in CVE-2026-55747 (CVE-2026-55747). Confidential information can be exposed externally.
|
| CVE-2026-16940 |
|
Path Traversal in wordpress (CVE-2026-16940)
path traversal in wordpress (CVE-2026-16940). Data can be tampered with by attackers.
|
| CVE-2026-18903 |
|
Path Traversal in path-traversal (CVE-2026-18903)
path traversal in path-traversal (CVE-2026-18903). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18853 |
|
Path Traversal in c (CVE-2026-18853)
path traversal in c (CVE-2026-18853). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70593 |
|
Path Traversal in ghost (CVE-2026-70593)
path traversal in ghost (CVE-2026-70593). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70592 |
|
Path Traversal in ghost (CVE-2026-70592)
path traversal in ghost (CVE-2026-70592). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-47682 |
|
Path Traversal in CVE-2026-47682 (CVE-2026-47682)
path traversal in CVE-2026-47682 (CVE-2026-47682). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47612 |
|
Path Traversal in nvidia (CVE-2026-47612)
path traversal in nvidia (CVE-2026-47612). Confidential information can be exposed externally.
|
| CVE-2026-47487 |
|
Path Traversal in dos (CVE-2026-47487)
path traversal in dos (CVE-2026-47487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58072 |
|
Path Traversal in CVE-2026-58072 (CVE-2026-58072)
path traversal in CVE-2026-58072 (CVE-2026-58072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69110 |
|
Path Traversal in CVE-2026-69110 (CVE-2026-69110)
path traversal in CVE-2026-69110 (CVE-2026-69110). Confidential information can be exposed externally. Exploitable via `GET /api/tmp/`.
|
| CVE-2026-67200 |
|
Path Traversal in path-traversal (CVE-2026-67200)
path traversal in path-traversal (CVE-2026-67200). Confidential information can be exposed externally.
|
| CVE-2026-14194 |
|
Path Traversal in path-traversal (CVE-2026-14194)
path traversal in path-traversal (CVE-2026-14194). Confidential information can be exposed externally.
|
| CVE-2026-14818 |
|
Path Traversal in path-traversal (CVE-2026-14818)
path traversal in path-traversal (CVE-2026-14818). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17614 |
|
Path Traversal in path-traversal (CVE-2026-17614)
path traversal in path-traversal (CVE-2026-17614). Confidential information can be exposed externally.
|
| CVE-2026-56845 |
|
Path Traversal in path-traversal (CVE-2026-56845)
path traversal in path-traversal (CVE-2026-56845). Confidential information can be exposed externally.
|
| CVE-2026-18648 |
|
Path Traversal in react (CVE-2026-18648)
path traversal in react (CVE-2026-18648). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18645 |
|
Path Traversal in path-traversal (CVE-2026-18645)
path traversal in path-traversal (CVE-2026-18645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18646 |
|
Path Traversal in path-traversal (CVE-2026-18646)
path traversal in path-traversal (CVE-2026-18646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18644 |
|
Path Traversal in path-traversal (CVE-2026-18644)
path traversal in path-traversal (CVE-2026-18644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61372 |
|
Path Traversal in apache (CVE-2026-61372)
path traversal in apache (CVE-2026-61372). Confidential information can be exposed externally.
|
| CVE-2026-69153 |
|
Path Traversal in postcss (CVE-2026-69153)
path traversal in postcss (CVE-2026-69153). Risk of unauthorized operations or information disclosure. Exploitable via ``sourceMappingURL``. Mitigation: upgrade to `8.5.23` or later.
|
| CVE-2026-69095 |
|
Path Traversal in path-traversal (CVE-2026-69095)
path traversal in path-traversal (CVE-2026-69095). Confidential information can be exposed externally.
|
| CVE-2026-69086 |
|
Path Traversal in CVE-2026-69086 (CVE-2026-69086)
path traversal in CVE-2026-69086 (CVE-2026-69086). Confidential information can be exposed externally.
|
| CVE-2026-69089 |
|
Path Traversal in path-traversal (CVE-2026-69089)
path traversal in path-traversal (CVE-2026-69089). Confidential information can be exposed externally.
|
| CVE-2025-15673 |
|
Path Traversal in wordpress (CVE-2025-15673)
path traversal in wordpress (CVE-2025-15673). Confidential information can be exposed externally.
|
| CVE-2026-9856 |
|
Path Traversal in path-traversal (CVE-2026-9856)
path traversal in path-traversal (CVE-2026-9856). Data can be tampered with by attackers. Exploitable via ``PreTrainedTokenizerBase``.
|
| CVE-2026-9335 |
|
Path Traversal in keras (CVE-2026-9335)
path traversal in keras (CVE-2026-9335). Confidential information can be exposed externally. Exploitable via ``KerasFileEditor``. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-13339 |
|
Path Traversal in wordpress (CVE-2026-13339)
path traversal in wordpress (CVE-2026-13339). Confidential information can be exposed externally.
|
| CVE-2026-18352 |
|
Path Traversal in wordpress (CVE-2026-18352)
path traversal in wordpress (CVE-2026-18352). Confidential information can be exposed externally.
|
| CVE-2026-67309 |
|
Path Traversal in github.com/traefik/traefik/v3 (CVE-2026-67309)
path traversal in github.com/traefik/traefik/v3 (CVE-2026-67309). Risk of unauthorized operations or information disclosure. Exploitable via ``RewriteTarget``. Mitigation: upgrade to `3.7.8` or later.
|
| CVE-2026-67295 |
|
Path Traversal in CVE-2026-67295 (CVE-2026-67295)
path traversal in CVE-2026-67295 (CVE-2026-67295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15450 |
|
Path Traversal in wordpress (CVE-2026-15450)
path traversal in wordpress (CVE-2026-15450). Data can be tampered with by attackers.
|
| CVE-2026-15601 |
|
Path Traversal in wordpress (CVE-2026-15601)
path traversal in wordpress (CVE-2026-15601). Confidential information can be exposed externally.
|
| CVE-2026-15244 |
|
Path Traversal in c (CVE-2026-15244)
path traversal in c (CVE-2026-15244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15932 |
|
Path Traversal in wordpress (CVE-2026-15932)
path traversal in wordpress (CVE-2026-15932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-54785 |
|
Path Traversal in gemini-bridge (CVE-2026-54785)
path traversal in gemini-bridge (CVE-2026-54785). Confidential information can be exposed externally. Exploitable via ``consult_gemini_with_files``. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-62999 |
|
Path Traversal in CVE-2026-62999 (CVE-2026-62999)
path traversal in CVE-2026-62999 (CVE-2026-62999). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55825 |
|
Path Traversal in contao/contao (CVE-2026-55825)
path traversal in contao/contao (CVE-2026-55825). Risk of unauthorized operations or information disclosure. Exploitable via ``jobUuid``. Mitigation: upgrade to `5.7.7` or later.
|
| CVE-2026-53502 |
|
Path Traversal in thumbor (CVE-2026-53502)
path traversal in thumbor (CVE-2026-53502). Risk of unauthorized operations or information disclosure. Exploitable via ``imaging.py``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-62391 |
|
Path Traversal in apache (CVE-2026-62391)
path traversal in apache (CVE-2026-62391). Confidential information can be exposed externally.
|
| CVE-2026-44615 |
|
Path Traversal in apache (CVE-2026-44615)
path traversal in apache (CVE-2026-44615). Confidential information can be exposed externally.
|
| CVE-2026-63222 |
|
Path Traversal in codeigniter4/framework (CVE-2026-63222)
path traversal in codeigniter4/framework (CVE-2026-63222). Data can be tampered with by attackers. Mitigation: upgrade to `4.7.4` or later.
|
| CVE-2026-56673 |
|
Path Traversal in CVE-2026-56673 (CVE-2026-56673)
path traversal in CVE-2026-56673 (CVE-2026-56673). Confidential information can be exposed externally. Exploitable via `POST /prompt`.
|
| CVE-2026-56671 |
|
Path Traversal in CVE-2026-56671 (CVE-2026-56671)
path traversal in CVE-2026-56671 (CVE-2026-56671). Confidential information can be exposed externally.
|
| CVE-2026-66755 |
|
Path Traversal in apache (CVE-2026-66755)
path traversal in apache (CVE-2026-66755). Confidential information can be exposed externally.
|
| CVE-2026-12942 |
|
Path Traversal in langflow (CVE-2026-12942)
path traversal in langflow (CVE-2026-12942). Confidential information can be exposed externally.
|
| CVE-2026-52680 |
|
Path Traversal in apache (CVE-2026-52680)
path traversal in apache (CVE-2026-52680). Successful exploitation can lead to full system takeover.
|