Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39405 |
|
Path Traversal in CVE-2026-39405 (CVE-2026-39405)
path traversal in CVE-2026-39405 (CVE-2026-39405). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24208 |
|
Path Traversal in path-traversal (CVE-2026-24208)
path traversal in path-traversal (CVE-2026-24208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24209 |
|
Path Traversal in path-traversal (CVE-2026-24209)
path traversal in path-traversal (CVE-2026-24209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35593 |
|
Path Traversal in CVE-2026-35593 (CVE-2026-35593)
path traversal in CVE-2026-35593 (CVE-2026-35593). Confidential information can be exposed externally.
|
| CVE-2026-46338 |
|
Path Traversal in pymdown-extensions (CVE-2026-46338)
path traversal in pymdown-extensions (CVE-2026-46338). Risk of unauthorized operations or information disclosure. Exploitable via ``pymdownx.snippets``. Mitigation: upgrade to `10.21.3` or later.
|
| CVE-2026-36829 |
|
Path Traversal in path-traversal (CVE-2026-36829)
path traversal in path-traversal (CVE-2026-36829). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46337 |
|
Path Traversal in WWBN/AVideo (CVE-2026-46337)
path traversal in WWBN/AVideo (CVE-2026-46337). Risk of unauthorized operations or information disclosure. Exploitable via `GET /view/img/image404Raw.php`.
|
| CVE-2026-45711 |
|
Path Traversal in github.com/axllent/mailpit (CVE-2026-45711)
path traversal in github.com/axllent/mailpit (CVE-2026-45711). Data can be tampered with by attackers. Mitigation: upgrade to `1.30.0` or later.
|
| CVE-2026-45576 |
|
Path Traversal in github.com/openziti/zrok/v2 (CVE-2026-45576)
path traversal in github.com/openziti/zrok/v2 (CVE-2026-45576). Data can be tampered with by attackers. Exploitable via ``href``. Mitigation: upgrade to `2.0.3` or later.
|
| CVE-2026-45571 |
|
Path Traversal in github.com/go-git/go-git/v5 (CVE-2026-45571)
path traversal in github.com/go-git/go-git/v5 (CVE-2026-45571). Risk of unauthorized operations or information disclosure. Exploitable via ``Storer``. Mitigation: upgrade to `5.19.1` or later.
|
| CVE-2025-70950 |
|
Path Traversal in github.com/itang/gohttp (CVE-2025-70950)
path traversal in github.com/itang/gohttp (CVE-2025-70950). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45568 |
|
Path Traversal in zrok (CVE-2026-45568)
path traversal in zrok (CVE-2026-45568). Confidential information can be exposed externally. Exploitable via ``ProxyShare``.
|
| CVE-2026-46724 |
|
Path Traversal in tpwd/ke_search (CVE-2026-46724)
path traversal in tpwd/ke_search (CVE-2026-46724). Risk of unauthorized operations or information disclosure. Exploitable via ``ke_search``. Mitigation: upgrade to `4.6.7` or later.
|
| CVE-2026-31379 |
|
Path Traversal in apache (CVE-2026-31379)
path traversal in apache (CVE-2026-31379). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29220 |
|
Path Traversal in apache (CVE-2026-29220)
path traversal in apache (CVE-2026-29220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47091 |
|
Path Traversal in path-traversal (CVE-2026-47091)
path traversal in path-traversal (CVE-2026-47091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45731 |
|
Path Traversal in WWBN/AVideo (CVE-2026-45731)
path traversal in WWBN/AVideo (CVE-2026-45731). Confidential information can be exposed externally. Exploitable via `POST /view/update.php`.
|
| CVE-2026-29963 |
|
Path Traversal in path-traversal (CVE-2026-29963)
path traversal in path-traversal (CVE-2026-29963). Confidential information can be exposed externally.
|
| CVE-2026-45230 |
|
Path Traversal in path-traversal (CVE-2026-45230)
path traversal in path-traversal (CVE-2026-45230). Data can be tampered with by attackers. Exploitable via `POST /api/delete-file`.
|
| CVE-2026-45727 |
|
Path Traversal in cloakbrowser (CVE-2026-45727)
path traversal in cloakbrowser (CVE-2026-45727). Risk of unauthorized operations or information disclosure. Exploitable via ``cloakserve``. Mitigation: upgrade to `0.3.28` or later.
|
| CVE-2026-20685 |
|
Vulnerability in apple (CVE-2026-20685)
vulnerability in apple (CVE-2026-20685). Confidential information can be exposed externally.
|
| CVE-2026-8802 |
|
Path Traversal in path-traversal (CVE-2026-8802)
path traversal in path-traversal (CVE-2026-8802). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6381 |
|
Path Traversal in wordpress (CVE-2026-6381)
path traversal in wordpress (CVE-2026-6381). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8770 |
|
Path Traversal in path-traversal (CVE-2026-8770)
path traversal in path-traversal (CVE-2026-8770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8765 |
|
Path Traversal in path-traversal (CVE-2026-8765)
path traversal in path-traversal (CVE-2026-8765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8757 |
|
Path Traversal in path-traversal (CVE-2026-8757)
path traversal in path-traversal (CVE-2026-8757). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8754 |
|
Path Traversal in AstrBot (CVE-2026-8754)
path traversal in AstrBot (CVE-2026-8754). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.23.6` or later.
|
| CVE-2026-8755 |
|
Path Traversal in path-traversal (CVE-2026-8755)
path traversal in path-traversal (CVE-2026-8755). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8756 |
|
Path Traversal in path-traversal (CVE-2026-8756)
path traversal in path-traversal (CVE-2026-8756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25326 |
|
Path Traversal in wordpress (CVE-2018-25326)
path traversal in wordpress (CVE-2018-25326). Confidential information can be exposed externally.
|
| CVE-2018-25325 |
|
Path Traversal in wordpress (CVE-2018-25325)
path traversal in wordpress (CVE-2018-25325). Confidential information can be exposed externally.
|
| CVE-2026-8736 |
|
Path Traversal in path-traversal (CVE-2026-8736)
path traversal in path-traversal (CVE-2026-8736). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47977 |
|
Path Traversal in wordpress (CVE-2021-47977)
path traversal in wordpress (CVE-2021-47977). Confidential information can be exposed externally.
|
| CVE-2021-47979 |
|
Path Traversal in c (CVE-2021-47979)
path traversal in c (CVE-2021-47979). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47942 |
|
Path Traversal in path-traversal (CVE-2021-47942)
path traversal in path-traversal (CVE-2021-47942). Confidential information can be exposed externally.
|
| CVE-2026-46703 |
|
Path Traversal in boxlite (CVE-2026-46703)
path traversal in boxlite (CVE-2026-46703). Successful exploitation can lead to full system takeover. Exploitable via ``apply_oci_layer``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-46383 |
|
Path Traversal in apm-cli (CVE-2026-46383)
path traversal in apm-cli (CVE-2026-46383). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2026-46491 |
|
Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
path traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491). Data can be tampered with by attackers. Exploitable via ``ticket``. Mitigation: upgrade to `7.0.3` or later.
|
| CVE-2026-44641 |
|
Path Traversal in apm-cli (CVE-2026-44641)
path traversal in apm-cli (CVE-2026-44641). Confidential information can be exposed externally. Exploitable via ``agents``. Mitigation: upgrade to `0.8.12` or later.
|
| CVE-2026-44716 |
|
Path Traversal in pipecat-ai (CVE-2026-44716)
path traversal in pipecat-ai (CVE-2026-44716). Confidential information can be exposed externally. Exploitable via `GET /files/{filename`. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-7182 |
|
Path Traversal in path-traversal (CVE-2026-7182)
path traversal in path-traversal (CVE-2026-7182). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41552 |
|
Path Traversal in path-traversal (CVE-2026-41552)
path traversal in path-traversal (CVE-2026-41552). Confidential information can be exposed externally.
|
| CVE-2026-6403 |
|
Path Traversal in wordpress (CVE-2026-6403)
path traversal in wordpress (CVE-2026-6403). Confidential information can be exposed externally.
|
| CVE-2026-44647 |
|
Path Traversal in CVE-2026-44647 (CVE-2026-44647)
path traversal in CVE-2026-44647 (CVE-2026-44647). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `15.0.2` or later.
|
| CVE-2026-44522 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/notes/{noteID}/assets`. Mitigation: upgrade to `0.0.0-20260501152243-db3f72bff780` or later.
|
| CVE-2026-44973 |
|
Path Traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973)
path traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973). Confidential information can be exposed externally. Exploitable via ``osfs.ChrootOS``. Mitigation: upgrade to `5.9.0` or later.
|
| CVE-2026-44542 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542)
path traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542). Data can be tampered with by attackers. Exploitable via `DELETE /public/api/resources`. Mitigation: upgrade to `0.0.0-20260501183844-112740bdd41d` or later.
|
| CVE-2026-42598 |
|
Path Traversal in c (CVE-2026-42598)
path traversal in c (CVE-2026-42598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-44885 |
|
Path Traversal in github.com/portainer/portainer (CVE-2026-44885)
path traversal in github.com/portainer/portainer (CVE-2026-44885). Data can be tampered with by attackers. Exploitable via ``ExtractTarGz``. Mitigation: upgrade to `2.33.8` or later.
|
| CVE-2026-42593 |
|
Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-42593)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-42593). Risk of unauthorized operations or information disclosure. Exploitable via ``stamp``.
|