Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48716 |
|
Path Traversal in CVE-2026-48716 (CVE-2026-48716)
path traversal in CVE-2026-48716 (CVE-2026-48716). Data can be tampered with by attackers.
|
| CVE-2026-54319 |
|
Vulnerability in github.com/daytonaio/daytona (CVE-2026-54319)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54319). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.186.0` or later.
|
| CVE-2026-54223 |
|
Path Traversal in path-traversal (CVE-2026-54223)
path traversal in path-traversal (CVE-2026-54223). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8811 |
|
Path Traversal in CVE-2026-8811 (CVE-2026-8811)
path traversal in CVE-2026-8811 (CVE-2026-8811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12568 |
|
Path Traversal in bbot (CVE-2026-12568)
path traversal in bbot (CVE-2026-12568). Data can be tampered with by attackers. Exploitable via ``postman_download``. Mitigation: upgrade to `2.8.6` or later.
|
| CVE-2026-12565 |
|
Path Traversal in bbot (CVE-2026-12565)
path traversal in bbot (CVE-2026-12565). Data can be tampered with by attackers. Exploitable via ``unarchive``. Mitigation: upgrade to `2.8.5` or later.
|
| CVE-2026-48768 |
|
Path Traversal in CVE-2026-48768 (CVE-2026-48768)
path traversal in CVE-2026-48768 (CVE-2026-48768). Data can be tampered with by attackers. Exploitable via `POST /api/blocks/file-input/v3/generate-upload-url`.
|
| CVE-2026-48820 |
|
Path Traversal in cakephp/cakephp (CVE-2026-48820)
path traversal in cakephp/cakephp (CVE-2026-48820). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.11` or later.
|
| CVE-2026-55201 |
|
Path Traversal in path-traversal (CVE-2026-55201)
path traversal in path-traversal (CVE-2026-55201). Confidential information can be exposed externally.
|
| CVE-2026-49133 |
|
Path Traversal in path-traversal (CVE-2026-49133)
path traversal in path-traversal (CVE-2026-49133). Confidential information can be exposed externally.
|
| CVE-2026-55760 |
|
Path Traversal in com.github.jknack:handlebars (CVE-2026-55760)
path traversal in com.github.jknack:handlebars (CVE-2026-55760). Confidential information can be exposed externally. Mitigation: upgrade to `4.5.2` or later.
|
| CVE-2026-53872 |
|
Path Traversal in picklescan (CVE-2026-53872)
path traversal in picklescan (CVE-2026-53872). Confidential information can be exposed externally. Exploitable via ``picklescan``. Mitigation: upgrade to `0.0.35` or later.
|
| CVE-2026-54193 |
|
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
|
| CVE-2026-52716 |
|
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
|
| CVE-2025-69128 |
|
Path Traversal in path-traversal (CVE-2025-69128)
path traversal in path-traversal (CVE-2025-69128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9690 |
|
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
|
| CVE-2026-50203 |
|
Path Traversal in apache-airflow-providers-sftp (CVE-2026-50203)
path traversal in apache-airflow-providers-sftp (CVE-2026-50203). Confidential information can be exposed externally. Exploitable via ``SFTPHook.retrieve_directory``. Mitigation: upgrade to `5.8.1` or later.
|
| CVE-2026-40724 |
|
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
|
| CVE-2026-27400 |
|
Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.
Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.
|
| CVE-2026-22334 |
|
Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.
Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.
|
| CVE-2026-10094 |
|
Path Traversal in path-traversal (CVE-2026-10094)
path traversal in path-traversal (CVE-2026-10094). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69139 |
|
Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.
Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.
|
| CVE-2025-60223 |
|
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
|
| CVE-2025-69131 |
|
Path Traversal in wordpress (CVE-2025-69131)
path traversal in wordpress (CVE-2025-69131). Confidential information can be exposed externally.
|
| CVE-2024-32729 |
|
Path Traversal in path-traversal (CVE-2024-32729)
path traversal in path-traversal (CVE-2024-32729). Confidential information can be exposed externally.
|
| CVE-2026-54017 |
|
Path Traversal in open-webui (CVE-2026-54017)
path traversal in open-webui (CVE-2026-54017). Confidential information can be exposed externally. Exploitable via `GET /api/v1/terminals/server1/..`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-20181 |
|
Path Traversal in Cisco dos (CVE-2026-20181)
path traversal in Cisco dos (CVE-2026-20181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54014 |
|
Path Traversal in open-webui (CVE-2026-54014)
path traversal in open-webui (CVE-2026-54014). Risk of unauthorized operations or information disclosure. Exploitable via `GET /cache/{{path}}`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-48055 |
|
Vulnerability in path-traversal (CVE-2026-48055)
vulnerability in path-traversal (CVE-2026-48055). Data can be tampered with by attackers.
|
| CVE-2026-47277 |
|
Path Traversal in CVE-2026-47277 (CVE-2026-47277)
path traversal in CVE-2026-47277 (CVE-2026-47277). Confidential information can be exposed externally.
|
| CVE-2026-48776 |
|
Path Traversal in langgraph-sdk (CVE-2026-48776)
path traversal in langgraph-sdk (CVE-2026-48776). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.15` or later.
|
| CVE-2026-52797 |
|
Path Traversal in gogs.io/gogs (CVE-2026-52797)
path traversal in gogs.io/gogs (CVE-2026-52797). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52844 |
|
Path Traversal in github.com/caddyserver/caddy/v2 (CVE-2026-52844)
path traversal in github.com/caddyserver/caddy/v2 (CVE-2026-52844). Confidential information can be exposed externally. Exploitable via `GET /private/secret.txt`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-49406 |
|
Path Traversal in deno (CVE-2026-49406)
path traversal in deno (CVE-2026-49406). Confidential information can be exposed externally. Exploitable via ``main``. Mitigation: upgrade to `2.7.12` or later.
|
| CVE-2026-49465 |
|
Path Traversal in n8n (CVE-2026-49465)
path traversal in n8n (CVE-2026-49465). Confidential information can be exposed externally. Exploitable via ``N8N_RESTRICT_FILE_ACCESS_TO``. Mitigation: upgrade to `2.21.8` or later.
|
| CVE-2026-42867 |
|
Path Traversal in langflow (CVE-2026-42867)
path traversal in langflow (CVE-2026-42867). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-54293 |
|
Path Traversal in nltk (CVE-2026-54293)
path traversal in nltk (CVE-2026-54293). Confidential information can be exposed externally. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-54286 |
|
Path Traversal in hono (CVE-2026-54286)
path traversal in hono (CVE-2026-54286). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.25` or later.
|
| CVE-2026-8442 |
|
Path Traversal in wordpress (CVE-2026-8442)
path traversal in wordpress (CVE-2026-8442). Data can be tampered with by attackers.
|
| CVE-2026-49766 |
|
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
|
| CVE-2026-49061 |
|
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
|
| CVE-2026-40779 |
|
Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.
Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.
|
| CVE-2026-40769 |
|
Path Traversal in CVE-2026-40769 (CVE-2026-40769)
path traversal in CVE-2026-40769 (CVE-2026-40769). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40727 |
|
Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
|
| CVE-2026-39489 |
|
Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
|
| CVE-2026-39468 |
|
Path Traversal in wordpress (CVE-2026-39468)
path traversal in wordpress (CVE-2026-39468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50877 |
|
Path Traversal in path-traversal (CVE-2026-50877)
path traversal in path-traversal (CVE-2026-50877). Confidential information can be exposed externally.
|
| CVE-2026-50869 |
|
Path Traversal in path-traversal (CVE-2026-50869)
path traversal in path-traversal (CVE-2026-50869). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53571 |
|
Path Traversal in vite (CVE-2026-53571)
path traversal in vite (CVE-2026-53571). Confidential information can be exposed externally. Exploitable via ``server.fs.deny``. Mitigation: upgrade to `6.4.3` or later.
|
| CVE-2026-49356 |
|
Path Traversal in @babel/core (CVE-2026-49356)
path traversal in @babel/core (CVE-2026-49356). Risk of unauthorized operations or information disclosure. Exploitable via ``inputSourceMap``. Mitigation: upgrade to `7.29.6` or later.
|