Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-22 Clear
ID Title
CVE-2026-50207 Path Traversal in acer (CVE-2026-50207)
path traversal in acer (CVE-2026-50207). Successful exploitation can lead to full system takeover.
CVE-2026-44023 Path Traversal in docling-core (CVE-2026-44023)
path traversal in docling-core (CVE-2026-44023). Confidential information can be exposed externally. Mitigation: upgrade to `2.74.1` or later.
CVE-2026-44022 Path Traversal in docling (CVE-2026-44022)
path traversal in docling (CVE-2026-44022). Confidential information can be exposed externally. Mitigation: upgrade to `2.91.0` or later.
CVE-2026-44017 Path Traversal in docling (CVE-2026-44017)
path traversal in docling (CVE-2026-44017). Successful exploitation can lead to full system takeover. Exploitable via ``SecurityError``. Mitigation: upgrade to `2.91.0` or later.
CVE-2024-47263 Path Traversal in path-traversal (CVE-2024-47263)
path traversal in path-traversal (CVE-2024-47263). Risk of unauthorized operations or information disclosure.
CVE-2024-47273 Path Traversal in path-traversal (CVE-2024-47273)
path traversal in path-traversal (CVE-2024-47273). Risk of unauthorized operations or information disclosure.
CVE-2026-35082 Path Traversal in mbs-solutions (CVE-2026-35082)
path traversal in mbs-solutions (CVE-2026-35082). Successful exploitation can lead to full system takeover.
CVE-2026-41412 Path Traversal in CVE-2026-41412 (CVE-2026-41412)
path traversal in CVE-2026-41412 (CVE-2026-41412). Confidential information can be exposed externally. Exploitable via ``simpleHttpClient``.
CVE-2026-49144 Path Traversal in browserstack-runner (CVE-2026-49144)
path traversal in browserstack-runner (CVE-2026-49144). Confidential information can be exposed externally. Exploitable via ``_default``.
CVE-2026-35718 Path Traversal in path-traversal (CVE-2026-35718)
path traversal in path-traversal (CVE-2026-35718). Confidential information can be exposed externally.
CVE-2026-43965 Path Traversal in path-traversal (CVE-2026-43965)
path traversal in path-traversal (CVE-2026-43965). Risk of unauthorized operations or information disclosure.
CVE-2026-32685 Path Traversal in path-traversal (CVE-2026-32685)
path traversal in path-traversal (CVE-2026-32685). Risk of unauthorized operations or information disclosure.
CVE-2026-0055 Path Traversal in path-traversal (CVE-2026-0055)
path traversal in path-traversal (CVE-2026-0055). Confidential information can be exposed externally.
CVE-2026-49136 Path Traversal in path-traversal (CVE-2026-49136)
path traversal in path-traversal (CVE-2026-49136). Confidential information can be exposed externally.
CVE-2026-45279 Path Traversal in path-traversal (CVE-2026-45279)
path traversal in path-traversal (CVE-2026-45279). Confidential information can be exposed externally.
CVE-2026-43624 Path Traversal in path-traversal (CVE-2026-43624)
path traversal in path-traversal (CVE-2026-43624). Data can be tampered with by attackers.
CVE-2026-10278 Path Traversal in path-traversal (CVE-2026-10278)
path traversal in path-traversal (CVE-2026-10278). Risk of unauthorized operations or information disclosure.
CVE-2026-8643 Path Traversal in pip (CVE-2026-8643)
path traversal in pip (CVE-2026-8643). Data can be tampered with by attackers. Mitigation: upgrade to `26.1.2` or later.
CVE-2026-42679 Path Traversal in path-traversal (CVE-2026-42679)
path traversal in path-traversal (CVE-2026-42679). Confidential information can be exposed externally.
CVE-2026-48866 Path Traversal in path-traversal (CVE-2026-48866)
path traversal in path-traversal (CVE-2026-48866). Successful exploitation can lead to full system takeover.
CVE-2026-10264 Path Traversal in path-traversal (CVE-2026-10264)
path traversal in path-traversal (CVE-2026-10264). Risk of unauthorized operations or information disclosure.
CVE-2024-40646 Path Traversal in path-traversal (CVE-2024-40646)
path traversal in path-traversal (CVE-2024-40646). Confidential information can be exposed externally.
CVE-2026-47425 Path Traversal in rattler (CVE-2026-47425)
path traversal in rattler (CVE-2026-47425). Risk of unauthorized operations or information disclosure. Exploitable via ``rattler_conda_types``. Mitigation: upgrade to `0.43.2` or later.
CVE-2026-47429 Path Traversal in vitest (CVE-2026-47429)
path traversal in vitest (CVE-2026-47429). Successful exploitation can lead to full system takeover. Exploitable via ``api.host``. Mitigation: upgrade to `3.2.6` or later.
CVE-2026-48827 Path Traversal in org.apache.sshd:sshd-git (CVE-2026-48827)
path traversal in org.apache.sshd:sshd-git (CVE-2026-48827). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-M4` or later.
CVE-2026-40547 Path Traversal in path-traversal (CVE-2026-40547)
path traversal in path-traversal (CVE-2026-40547). Risk of unauthorized operations or information disclosure.
CVE-2026-10213 Path Traversal in path-traversal (CVE-2026-10213)
path traversal in path-traversal (CVE-2026-10213). Risk of unauthorized operations or information disclosure.
CVE-2018-25421 Path Traversal in path-traversal (CVE-2018-25421)
path traversal in path-traversal (CVE-2018-25421). Confidential information can be exposed externally.
CVE-2018-25408 Path Traversal in path-traversal (CVE-2018-25408)
path traversal in path-traversal (CVE-2018-25408). Confidential information can be exposed externally.
CVE-2026-47397 Path Traversal in PraisonAI (CVE-2026-47397)
path traversal in PraisonAI (CVE-2026-47397). Risk of unauthorized operations or information disclosure. Exploitable via ``write_file``. Mitigation: upgrade to `4.6.40` or later.
CVE-2026-47394 Path Traversal in PraisonAI (CVE-2026-47394)
path traversal in PraisonAI (CVE-2026-47394). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai.rules.create``. Mitigation: upgrade to `4.6.40` or later.
CVE-2026-47121 Path Traversal in github.com/sparkle-project/Sparkle (CVE-2026-47121)
path traversal in github.com/sparkle-project/Sparkle (CVE-2026-47121). Data can be tampered with by attackers. Exploitable via ``Extract``. Mitigation: upgrade to `2.9.2` or later.
CVE-2026-10108 Path Traversal in xiaomusic (CVE-2026-10108)
path traversal in xiaomusic (CVE-2026-10108). Confidential information can be exposed externally. Exploitable via `GET /music/{file_path`. Mitigation: upgrade to `0.5.8` or later.
CVE-2026-45661 Path Traversal in path-traversal (CVE-2026-45661)
path traversal in path-traversal (CVE-2026-45661). Successful exploitation can lead to full system takeover.
CVE-2026-45668 Path Traversal in path-traversal (CVE-2026-45668)
path traversal in path-traversal (CVE-2026-45668). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.102.2` or later.
CVE-2026-44829 Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829). Data can be tampered with by attackers. Exploitable via ``filepath.Base``. Mitigation: upgrade to `8.33.0` or later.
CVE-2026-39276 Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
CVE-2018-25393 Path Traversal in path-traversal (CVE-2018-25393)
path traversal in path-traversal (CVE-2018-25393). Confidential information can be exposed externally.
CVE-2026-9559 Path Traversal in mautic/core (CVE-2026-9559)
path traversal in mautic/core (CVE-2026-9559). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.2` or later.
CVE-2026-47179 Path Traversal in github.com/getarcaneapp/arcane/backend (CVE-2026-47179)
path traversal in github.com/getarcaneapp/arcane/backend (CVE-2026-47179). Confidential information can be exposed externally. Mitigation: upgrade to `1.19.4` or later.
CVE-2026-42305 Path Traversal in dulwich (CVE-2026-42305)
path traversal in dulwich (CVE-2026-42305). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.5` or later.
CVE-2026-49128 Path Traversal in path-traversal (CVE-2026-49128)
path traversal in path-traversal (CVE-2026-49128). Confidential information can be exposed externally.
CVE-2026-32847 Path Traversal in path-traversal (CVE-2026-32847)
path traversal in path-traversal (CVE-2026-32847). Confidential information can be exposed externally. Exploitable via `GET /{full_path`.
CVE-2026-33462 Path Traversal in elk (CVE-2026-33462)
path traversal in elk (CVE-2026-33462). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.19.16, 9.3.5` or later.
CVE-2026-47144 Path Traversal in shamefile (CVE-2026-47144)
path traversal in shamefile (CVE-2026-47144). Confidential information can be exposed externally. Exploitable via ``shamefile.yaml``. Mitigation: upgrade to `0.1.7` or later.
CVE-2026-4944 Path Traversal in CVE-2026-4944 (CVE-2026-4944)
path traversal in CVE-2026-4944 (CVE-2026-4944). Successful exploitation can lead to full system takeover.
CVE-2026-46345 Path Traversal in compliance-trestle (CVE-2026-46345)
path traversal in compliance-trestle (CVE-2026-46345). Successful exploitation can lead to full system takeover. Exploitable via ``trestle``. Mitigation: upgrade to `3.12.2` or later.
CVE-2026-45774 Path Traversal in compliance-trestle (CVE-2026-45774)
path traversal in compliance-trestle (CVE-2026-45774). Risk of unauthorized operations or information disclosure. Exploitable via ``trestle_root``. Mitigation: upgrade to `3.12.2` or later.
CVE-2026-49238 Path Traversal in cpp (CVE-2026-49238)
path traversal in cpp (CVE-2026-49238). Confidential information can be exposed externally.
CVE-2026-9789 Path Traversal in privilege-escalation (CVE-2026-9789)
path traversal in privilege-escalation (CVE-2026-9789). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →