Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-63490 |
|
Path Traversal in CVE-2026-63490 (CVE-2026-63490)
path traversal in CVE-2026-63490 (CVE-2026-63490). Confidential information can be exposed externally.
|
| CVE-2026-70337 |
|
Vulnerability in path-traversal (CVE-2026-70337)
vulnerability in path-traversal (CVE-2026-70337). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65810 |
|
Vulnerability in csharp (CVE-2026-65810)
vulnerability in csharp (CVE-2026-65810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10595 |
|
Vulnerability in path-traversal (CVE-2026-10595)
vulnerability in path-traversal (CVE-2026-10595). Confidential information can be exposed externally. Exploitable via ``pathlib``.
|
| CVE-2026-55100 |
|
Vulnerability in hashi-vault-js (CVE-2026-55100)
vulnerability in hashi-vault-js (CVE-2026-55100). Risk of unauthorized operations or information disclosure. Exploitable via ``encodeURIComponent``. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-15802 |
|
Vulnerability in wordpress (CVE-2026-15802)
vulnerability in wordpress (CVE-2026-15802). Data can be tampered with by attackers.
|
| CVE-2026-58413 |
|
Path Traversal in network-ai (CVE-2026-58413)
path traversal in network-ai (CVE-2026-58413). Confidential information can be exposed externally. Exploitable via ``backupId``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58481 |
|
Path Traversal in network-ai (CVE-2026-58481)
path traversal in network-ai (CVE-2026-58481). Confidential information can be exposed externally. Exploitable via ``AgentRuntime``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-8023 |
|
Path Traversal in c (CVE-2026-8023)
path traversal in c (CVE-2026-8023). Confidential information can be exposed externally.
|
| CVE-2026-49290 |
|
Path Traversal in CVE-2026-49290 (CVE-2026-49290)
path traversal in CVE-2026-49290 (CVE-2026-49290). Risk of unauthorized operations or information disclosure. Exploitable via ``zipfile``.
|
| CVE-2026-8134 |
|
Vulnerability in concrete5/concrete5 (CVE-2026-8134)
vulnerability in concrete5/concrete5 (CVE-2026-8134). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-8209 |
|
Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32725 |
|
Vulnerability in c (CVE-2026-32725)
vulnerability in c (CVE-2026-32725). Confidential information can be exposed externally.
|