Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42219 |
|
Path Traversal in path-traversal (CVE-2026-42219)
path traversal in path-traversal (CVE-2026-42219). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41482 |
|
Path Traversal in path-traversal (CVE-2026-41482)
path traversal in path-traversal (CVE-2026-41482). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58499 |
|
Path Traversal in path-traversal (CVE-2026-58499)
path traversal in path-traversal (CVE-2026-58499). Data can be tampered with by attackers. Exploitable via `POST /api/v1/memory/add`.
|
| CVE-2026-55469 |
|
Path Traversal in snipe/snipe-it (CVE-2026-55469)
path traversal in snipe/snipe-it (CVE-2026-55469). Data can be tampered with by attackers. Exploitable via ``import``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-73498 |
|
Path Traversal in mcp-atlassian (CVE-2026-73498)
path traversal in mcp-atlassian (CVE-2026-73498). Confidential information can be exposed externally. Exploitable via ``confluence_upload_attachment``. Mitigation: upgrade to `0.22.0` or later.
|
| CVE-2025-70796 |
|
Path Traversal in path-traversal (CVE-2025-70796)
path traversal in path-traversal (CVE-2025-70796). Confidential information can be exposed externally.
|
| CVE-2026-61432 |
|
Path Traversal in path-traversal (CVE-2026-61432)
path traversal in path-traversal (CVE-2026-61432). Confidential information can be exposed externally.
|
| CVE-2026-61431 |
|
Path Traversal in path-traversal (CVE-2026-61431)
path traversal in path-traversal (CVE-2026-61431). Confidential information can be exposed externally.
|
| CVE-2026-60089 |
|
Path Traversal in CVE-2026-60089 (CVE-2026-60089)
path traversal in CVE-2026-60089 (CVE-2026-60089). Data can be tampered with by attackers.
|
| CVE-2026-57961 |
|
Path Traversal in path-traversal (CVE-2026-57961)
path traversal in path-traversal (CVE-2026-57961). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54468 |
|
Path Traversal in path-traversal (CVE-2026-54468)
path traversal in path-traversal (CVE-2026-54468). Confidential information can be exposed externally.
|
| CVE-2026-13347 |
|
Path Traversal in wordpress (CVE-2026-13347)
path traversal in wordpress (CVE-2026-13347). Confidential information can be exposed externally.
|
| CVE-2026-40005 |
|
Path Traversal in apache (CVE-2026-40005)
path traversal in apache (CVE-2026-40005). Confidential information can be exposed externally.
|
| CVE-2026-15331 |
|
Path Traversal in path-traversal (CVE-2026-15331)
path traversal in path-traversal (CVE-2026-15331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15326 |
|
Path Traversal in path-traversal (CVE-2026-15326)
path traversal in path-traversal (CVE-2026-15326). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59832 |
|
Path Traversal in CVE-2026-59832 (CVE-2026-59832)
path traversal in CVE-2026-59832 (CVE-2026-59832). Confidential information can be exposed externally.
|
| CVE-2026-39245 |
|
Path Traversal in path-traversal (CVE-2026-39245)
path traversal in path-traversal (CVE-2026-39245). Data can be tampered with by attackers.
|
| CVE-2026-13492 |
|
Path Traversal in wordpress (CVE-2026-13492)
path traversal in wordpress (CVE-2026-13492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59149 |
|
Path Traversal in CVE-2026-59149 (CVE-2026-59149)
path traversal in CVE-2026-59149 (CVE-2026-59149). Confidential information can be exposed externally.
|
| CVE-2026-15204 |
|
Path Traversal in path-traversal (CVE-2026-15204)
path traversal in path-traversal (CVE-2026-15204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59221 |
|
Path Traversal in open-webui (CVE-2026-59221)
path traversal in open-webui (CVE-2026-59221). Confidential information can be exposed externally. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-14372 |
|
Path Traversal in wordpress (CVE-2026-14372)
path traversal in wordpress (CVE-2026-14372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47826 |
|
Path Traversal in cloudfoundry (CVE-2026-47826)
path traversal in cloudfoundry (CVE-2026-47826). Confidential information can be exposed externally.
|
| CVE-2026-15138 |
|
Path Traversal in path-traversal (CVE-2026-15138)
path traversal in path-traversal (CVE-2026-15138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58192 |
|
Path Traversal in appium (CVE-2026-58192)
path traversal in appium (CVE-2026-58192). Data can be tampered with by attackers. Exploitable via `POST /storage/delete`.
|
| CVE-2026-54591 |
|
Path Traversal in asyncssh (CVE-2026-54591)
path traversal in asyncssh (CVE-2026-54591). Data can be tampered with by attackers. Exploitable via ``_parse_cd_args``. Mitigation: upgrade to `2.23.1` or later.
|
| CVE-2026-54590 |
|
Path Traversal in asyncssh (CVE-2026-54590)
path traversal in asyncssh (CVE-2026-54590). Data can be tampered with by attackers. Exploitable via ``AuthorizedKeysFile``. Mitigation: upgrade to `2.23.0` or later.
|
| CVE-2026-59948 |
|
Path Traversal in composer/composer (CVE-2026-59948)
path traversal in composer/composer (CVE-2026-59948). Successful exploitation can lead to full system takeover. Exploitable via ``install``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59946 |
|
Path Traversal in composer/composer (CVE-2026-59946)
path traversal in composer/composer (CVE-2026-59946). Confidential information can be exposed externally. Exploitable via ``bin``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59820 |
|
Path Traversal in litellm (CVE-2026-59820)
path traversal in litellm (CVE-2026-59820). Data can be tampered with by attackers. Exploitable via `POST /v1/skills`. Mitigation: upgrade to `1.83.7-stable` or later.
|
| CVE-2026-59924 |
|
Path Traversal in mistune (CVE-2026-59924)
path traversal in mistune (CVE-2026-59924). Confidential information can be exposed externally. Exploitable via ``Include``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-53951 |
|
Path Traversal in copier (CVE-2026-53951)
path traversal in copier (CVE-2026-53951). Risk of unauthorized operations or information disclosure. Exploitable via ``trust``. Mitigation: upgrade to `9.15.2` or later.
|
| CVE-2026-14967 |
|
Path Traversal in blacklanternsecurity (CVE-2026-14967)
path traversal in blacklanternsecurity (CVE-2026-14967). Risk of unauthorized operations or information disclosure. Exploitable via ``github_workflows``.
|
| CVE-2026-56273 |
|
Path Traversal in path-traversal (CVE-2026-56273)
path traversal in path-traversal (CVE-2026-56273). Data can be tampered with by attackers.
|
| CVE-2026-53480 |
|
Path Traversal in path-traversal (CVE-2026-53480)
path traversal in path-traversal (CVE-2026-53480). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22927 |
|
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
|
| CVE-2026-55874 |
|
Path Traversal in github.com/seaweedfs/seaweedfs (CVE-2026-55874)
path traversal in github.com/seaweedfs/seaweedfs (CVE-2026-55874). Confidential information can be exposed externally. Exploitable via ``CopyObject``. Mitigation: upgrade to `0.0.0-20260612000715-b44cf51fe931` or later.
|
| CVE-2026-55668 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55668)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55668). Data can be tampered with by attackers. Exploitable via `POST /api/resources/`. Mitigation: upgrade to `2.63.16` or later.
|
| CVE-2026-14500 |
|
Path Traversal in wordpress (CVE-2026-14500)
path traversal in wordpress (CVE-2026-14500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-14244 |
|
Path Traversal in wordpress (CVE-2026-14244)
path traversal in wordpress (CVE-2026-14244). Confidential information can be exposed externally.
|
| CVE-2026-55631 |
|
Path Traversal in path-traversal (CVE-2026-55631)
path traversal in path-traversal (CVE-2026-55631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53481 |
|
Path Traversal in path-traversal (CVE-2026-53481)
path traversal in path-traversal (CVE-2026-53481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42200 |
|
Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14468 |
|
Path Traversal in CVE-2026-14468 (CVE-2026-14468)
path traversal in CVE-2026-14468 (CVE-2026-14468). Confidential information can be exposed externally.
|
| CVE-2026-57571 |
|
Path Traversal in kidocode (CVE-2026-57571)
path traversal in kidocode (CVE-2026-57571). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54760 |
|
Path Traversal in langroid (CVE-2026-54760)
path traversal in langroid (CVE-2026-54760). Risk of unauthorized operations or information disclosure. Exploitable via ``_validate_query``. Mitigation: upgrade to `0.65.1` or later.
|
| CVE-2026-53486 |
|
Path Traversal in @xhmikosr/decompress (CVE-2026-53486)
path traversal in @xhmikosr/decompress (CVE-2026-53486). Confidential information can be exposed externally. Exploitable via ``path.relative``. Mitigation: upgrade to `11.1.3` or later.
|
| CVE-2026-9181 |
|
Path Traversal in path-traversal (CVE-2026-9181)
path traversal in path-traversal (CVE-2026-9181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59194 |
|
Path Traversal in pnpm (CVE-2026-59194)
path traversal in pnpm (CVE-2026-59194). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|