Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42780 |
|
Path Traversal in path-traversal (CVE-2026-42780)
path traversal in path-traversal (CVE-2026-42780). Data can be tampered with by attackers.
|
| CVE-2026-24464 |
|
Vulnerability in path-traversal (CVE-2026-24464)
vulnerability in path-traversal (CVE-2026-24464). Data can be tampered with by attackers.
|
| CVE-2020-37219 |
|
Path Traversal in path-traversal (CVE-2020-37219)
path traversal in path-traversal (CVE-2020-37219). Confidential information can be exposed externally.
|
| CVE-2026-25705 |
|
Vulnerability in github.com/rancher/rancher (CVE-2026-25705)
vulnerability in github.com/rancher/rancher (CVE-2026-25705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44307 |
|
Path Traversal in Mako (CVE-2026-44307)
path traversal in Mako (CVE-2026-44307). Risk of unauthorized operations or information disclosure. Exploitable via ``Template.__init__``. Mitigation: upgrade to `1.3.12` or later.
|
| CVE-2026-45225 |
|
Path Traversal in path-traversal (CVE-2026-45225)
path traversal in path-traversal (CVE-2026-45225). Data can be tampered with by attackers.
|
| CVE-2026-44258 |
|
OS Command Injection in path-traversal (CVE-2026-44258)
OS command injection in path-traversal (CVE-2026-44258). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.08.010` or later.
|
| CVE-2026-42196 |
|
Path Traversal in django-s3file (CVE-2026-42196)
path traversal in django-s3file (CVE-2026-42196). Risk of unauthorized operations or information disclosure. Exploitable via ``S3FileMiddleware``. Mitigation: upgrade to `7.0.2` or later.
|
| CVE-2026-7474 |
|
Path Traversal in github.com/hashicorp/nomad (CVE-2026-7474)
path traversal in github.com/hashicorp/nomad (CVE-2026-7474). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.11.0-rc.1.0.20260511152149-cd7240c4099a` or later.
|
| CVE-2026-34653 |
|
Path Traversal in path-traversal (CVE-2026-34653)
path traversal in path-traversal (CVE-2026-34653). Confidential information can be exposed externally.
|
| CVE-2026-34664 |
|
Path Traversal in path-traversal (CVE-2026-34664)
path traversal in path-traversal (CVE-2026-34664). Confidential information can be exposed externally.
|
| CVE-2026-41612 |
|
Path Traversal in path-traversal (CVE-2026-41612)
path traversal in path-traversal (CVE-2026-41612). Confidential information can be exposed externally.
|
| CVE-2026-42048 |
|
Path Traversal in langflow (CVE-2026-42048)
path traversal in langflow (CVE-2026-42048). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/knowledge_bases`. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-6865 |
|
Path Traversal in path-traversal (CVE-2026-6865)
path traversal in path-traversal (CVE-2026-6865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41551 |
|
Vulnerability in path-traversal (CVE-2026-41551)
vulnerability in path-traversal (CVE-2026-41551). Confidential information can be exposed externally.
|
| CVE-2026-0804 |
|
Vulnerability in path-traversal (CVE-2026-0804)
vulnerability in path-traversal (CVE-2026-0804). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42564 |
|
Path Traversal in path-traversal (CVE-2026-42564)
path traversal in path-traversal (CVE-2026-42564). Confidential information can be exposed externally. Mitigation: upgrade to `1.22.0` or later.
|
| CVE-2026-42600 |
|
Path Traversal in github.com/minio/minio (CVE-2026-42600)
path traversal in github.com/minio/minio (CVE-2026-42600). Confidential information can be exposed externally. Exploitable via ``ReadMultiple``.
|
| CVE-2026-42882 |
|
Path Traversal in github.com/oxyno-zeta/s3-proxy (CVE-2026-42882)
path traversal in github.com/oxyno-zeta/s3-proxy (CVE-2026-42882). Confidential information can be exposed externally. Exploitable via `PUT /upload/foo/drafts/../restricted/`. Mitigation: upgrade to `0.0.0-20260424211602-1320e4abd46a` or later.
|
| CVE-2026-45224 |
|
Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolution
Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolution
|
| CVE-2026-7819 |
|
Vulnerability in pgadmin4 (CVE-2026-7819)
vulnerability in pgadmin4 (CVE-2026-7819). Data can be tampered with by attackers. Mitigation: upgrade to `9.15` or later.
|
| CVE-2026-6815 |
|
Path Traversal in github.com/casdoor/casdoor (CVE-2026-6815)
path traversal in github.com/casdoor/casdoor (CVE-2026-6815). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42608 |
|
Path Traversal in getgrav/grav (CVE-2026-42608)
path traversal in getgrav/grav (CVE-2026-42608). Confidential information can be exposed externally. Exploitable via `POST /contact`. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2025-65418 |
|
Path Traversal in path-traversal (CVE-2025-65418)
path traversal in path-traversal (CVE-2025-65418). Confidential information can be exposed externally.
|
| CVE-2026-45033 |
|
Vulnerability in @github/copilot (CVE-2026-45033)
vulnerability in @github/copilot (CVE-2026-45033). Successful exploitation can lead to full system takeover. Exploitable via ``core.fsmonitor``. Mitigation: upgrade to `1.0.43` or later.
|
| CVE-2026-41951 |
|
Path Traversal in jvn (CVE-2026-41951)
path traversal in jvn (CVE-2026-41951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41530 |
|
Path Traversal in jvn (CVE-2026-41530)
path traversal in jvn (CVE-2026-41530). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8274 |
|
Path Traversal in c (CVE-2026-8274)
path traversal in c (CVE-2026-8274). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-50954 |
|
Vulnerability in wordpress (CVE-2022-50954)
vulnerability in wordpress (CVE-2022-50954). Confidential information can be exposed externally.
|
| CVE-2026-8215 |
|
Path Traversal in path-traversal (CVE-2026-8215)
path traversal in path-traversal (CVE-2026-8215). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42605 |
|
Path Traversal in azuracast/azuracast (CVE-2026-42605)
path traversal in azuracast/azuracast (CVE-2026-42605). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/station/{station_id}/files/upload`. Mitigation: upgrade to `0.23.6` or later.
|
| CVE-2026-6074 |
|
Vulnerability in cisa (CVE-2026-6074)
vulnerability in cisa (CVE-2026-6074). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8209 |
|
Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44788 |
|
Path Traversal in SharpCompress (CVE-2026-44788)
path traversal in SharpCompress (CVE-2026-44788). Data can be tampered with by attackers. Exploitable via ``WriteToDirectoryInternal``. Mitigation: upgrade to `0.48.0` or later.
|
| CVE-2026-42028 |
|
Path Traversal in path-traversal (CVE-2026-42028)
path traversal in path-traversal (CVE-2026-42028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38360 |
|
Path Traversal in path-traversal (CVE-2026-38360)
path traversal in path-traversal (CVE-2026-38360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42353 |
|
Path Traversal in i18next-http-middleware (CVE-2026-42353)
path traversal in i18next-http-middleware (CVE-2026-42353). Confidential information can be exposed externally. Exploitable via `GET /locales/resources.json`. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-44336 |
|
Vulnerability in praison (CVE-2026-44336)
vulnerability in praison (CVE-2026-44336). Successful exploitation can lead to full system takeover. Exploitable via ``praisonai.rules.create``.
|
| CVE-2026-44127 |
|
Vulnerability in path-traversal (CVE-2026-44127)
vulnerability in path-traversal (CVE-2026-44127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41491 |
|
Path Traversal in github.com/dapr/dapr (CVE-2026-41491)
path traversal in github.com/dapr/dapr (CVE-2026-41491). Confidential information can be exposed externally. Exploitable via ``purell.NormalizeURLString``. Mitigation: upgrade to `1.15.14` or later.
|
| CVE-2026-41493 |
|
Path Traversal in yard (CVE-2026-41493)
path traversal in yard (CVE-2026-41493). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.42` or later.
|
| CVE-2026-43944 |
|
Vulnerability in electerm (CVE-2026-43944)
vulnerability in electerm (CVE-2026-43944). Successful exploitation can lead to full system takeover. Exploitable via ``opts``. Mitigation: upgrade to `> 3.8.8` or later.
|
| CVE-2026-43940 |
|
Path Traversal in electerm (CVE-2026-43940)
path traversal in electerm (CVE-2026-43940). Successful exploitation can lead to full system takeover. Exploitable via ``runWidget``. Mitigation: upgrade to `3.7.16` or later.
|
| CVE-2026-42275 |
|
Path Traversal in github.com/openziti/zrok (CVE-2026-42275)
path traversal in github.com/openziti/zrok (CVE-2026-42275). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2026-8116 |
|
Path Traversal in path-traversal (CVE-2026-8116)
path traversal in path-traversal (CVE-2026-8116). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8115 |
|
Path Traversal in short-video-maker (CVE-2026-8115)
path traversal in short-video-maker (CVE-2026-8115). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8113 |
|
Path Traversal in path-traversal (CVE-2026-8113)
path traversal in path-traversal (CVE-2026-8113). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41691 |
|
Path Traversal in i18next-http-backend (CVE-2026-41691)
path traversal in i18next-http-backend (CVE-2026-41691). Risk of unauthorized operations or information disclosure. Exploitable via ``lng``. Mitigation: upgrade to `3.0.5` or later.
|
| CVE-2026-40982 |
|
Path Traversal in org.springframework.cloud:spring-cloud-config-server (CVE-2026-40982)
path traversal in org.springframework.cloud:spring-cloud-config-server (CVE-2026-40982). Confidential information can be exposed externally. Mitigation: upgrade to `5.0.3` or later.
|
| CVE-2026-35397 |
|
Path Traversal in jupyter-server (CVE-2026-35397)
path traversal in jupyter-server (CVE-2026-35397). Successful exploitation can lead to full system takeover. Exploitable via ``root_dir``. Mitigation: upgrade to `2.18.0` or later.
|