Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5436 |
|
Path Traversal in wordpress (CVE-2026-5436)
path traversal in wordpress (CVE-2026-5436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39844 |
|
Path Traversal in zauberzeug (CVE-2026-39844)
path traversal in zauberzeug (CVE-2026-39844). Data can be tampered with by attackers. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-39859 |
|
Path Traversal in liquidjs (CVE-2026-39859)
path traversal in liquidjs (CVE-2026-39859). Confidential information can be exposed externally. Mitigation: upgrade to `10.25.3` or later.
|
| CVE-2026-33466 |
|
Path Traversal in path-traversal (CVE-2026-33466)
path traversal in path-traversal (CVE-2026-33466). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39406 |
|
Path Traversal in hono (CVE-2026-39406)
path traversal in hono (CVE-2026-39406). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.13` or later.
|
| CVE-2026-39407 |
|
Path Traversal in hono (CVE-2026-39407)
path traversal in hono (CVE-2026-39407). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-39408 |
|
Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-3243 |
|
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
|
| CVE-2026-39847 |
|
Path Traversal in emmett (CVE-2026-39847)
path traversal in emmett (CVE-2026-39847). Confidential information can be exposed externally. Mitigation: upgrade to `2.8.1` or later.
|
| CVE-2026-39369 |
|
Path Traversal in WWBN/AVideo (CVE-2026-39369)
path traversal in WWBN/AVideo (CVE-2026-39369). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoderReceiveImage.json.php`.
|
| CVE-2026-34079 |
|
Path Traversal in flatpak (CVE-2026-34079)
path traversal in flatpak (CVE-2026-34079). Data can be tampered with by attackers. Mitigation: upgrade to `1.16.4` or later.
|
| CVE-2026-34371 |
|
Path Traversal in librechat (CVE-2026-34371)
path traversal in librechat (CVE-2026-34371). Data can be tampered with by attackers. Mitigation: upgrade to `0.8.4` or later.
|
| CVE-2026-39365 |
|
Path Traversal in vitejs (CVE-2026-39365)
path traversal in vitejs (CVE-2026-39365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.4.2` or later.
|
| CVE-2026-39345 |
|
Path Traversal in orangehrm (CVE-2026-39345)
path traversal in orangehrm (CVE-2026-39345). Confidential information can be exposed externally. Mitigation: upgrade to `5.8.1` or later.
|
| CVE-2026-35454 |
|
Path Traversal in github.com/coder/code-marketplace (CVE-2026-35454)
path traversal in github.com/coder/code-marketplace (CVE-2026-35454). Data can be tampered with by attackers. Exploitable via ``ExtractZip``. Mitigation: upgrade to `1.2.3-0.20260402184705-988440dee05f` or later.
|
| CVE-2026-35471 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35392 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35392)
path traversal in github.com/patrickhener/goshs (CVE-2026-35392). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35393 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35393)
path traversal in github.com/patrickhener/goshs (CVE-2026-35393). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35177 |
|
Path Traversal in c (CVE-2026-35177)
path traversal in c (CVE-2026-35177). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0280` or later.
|
| CVE-2026-35174 |
|
Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
|
| CVE-2026-5597 |
|
Path Traversal in path-traversal (CVE-2026-5597)
path traversal in path-traversal (CVE-2026-5597). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25687 |
|
Path Traversal in wisdom (CVE-2019-25687)
path traversal in wisdom (CVE-2019-25687). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25671 |
|
Path Traversal in c (CVE-2019-25671)
path traversal in c (CVE-2019-25671). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5595 |
|
Path Traversal in path-traversal (CVE-2026-5595)
path traversal in path-traversal (CVE-2026-5595). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5535 |
|
Path Traversal in path-traversal (CVE-2026-5535)
path traversal in path-traversal (CVE-2026-5535). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3666 |
|
Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34607 |
|
Path Traversal in path-traversal (CVE-2026-34607)
path traversal in path-traversal (CVE-2026-34607). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34978 |
|
Path Traversal in path-traversal (CVE-2026-34978)
path traversal in path-traversal (CVE-2026-34978). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26058 |
|
Path Traversal in path-traversal (CVE-2026-26058)
path traversal in path-traversal (CVE-2026-26058). Confidential information can be exposed externally.
|
| CVE-2026-22661 |
|
Path Traversal in path-traversal (CVE-2026-22661)
path traversal in path-traversal (CVE-2026-22661). Confidential information can be exposed externally.
|
| CVE-2026-28373 |
|
Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35214 |
|
Path Traversal in path-traversal (CVE-2026-35214)
path traversal in path-traversal (CVE-2026-35214). Data can be tampered with by attackers. Exploitable via `POST /api/plugin/upload`.
|
| CVE-2025-59711 |
|
Path Traversal in path-traversal (CVE-2025-59711)
path traversal in path-traversal (CVE-2025-59711). Confidential information can be exposed externally.
|
| CVE-2025-59709 |
|
Path Traversal in c (CVE-2025-59709)
path traversal in c (CVE-2025-59709). Confidential information can be exposed externally.
|
| CVE-2026-4350 |
|
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
|
| CVE-2026-34745 |
|
Path Traversal in shaneisrael (CVE-2026-34745)
path traversal in shaneisrael (CVE-2026-34745). Data can be tampered with by attackers.
|
| CVE-2026-34726 |
|
Path Traversal in path-traversal (CVE-2026-34726)
path traversal in path-traversal (CVE-2026-34726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34730 |
|
Path Traversal in copier-org (CVE-2026-34730)
path traversal in copier-org (CVE-2026-34730). Confidential information can be exposed externally.
|
| CVE-2026-34591 |
|
Path Traversal in python-poetry (CVE-2026-34591)
path traversal in python-poetry (CVE-2026-34591). Data can be tampered with by attackers.
|
| CVE-2026-34522 |
|
Path Traversal in path-traversal (CVE-2026-34522)
path traversal in path-traversal (CVE-2026-34522). Data can be tampered with by attackers.
|
| CVE-2026-34523 |
|
Path Traversal in path-traversal (CVE-2026-34523)
path traversal in path-traversal (CVE-2026-34523). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34524 |
|
Path Traversal in path-traversal (CVE-2026-34524)
path traversal in path-traversal (CVE-2026-34524). Confidential information can be exposed externally.
|
| CVE-2026-5344 |
|
Path Traversal in path-traversal (CVE-2026-5344)
path traversal in path-traversal (CVE-2026-5344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3987 |
|
Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27489 |
|
Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
|
| CVE-2026-41363 |
|
Path Traversal in openclaw (CVE-2026-41363)
path traversal in openclaw (CVE-2026-41363). Confidential information can be exposed externally. Mitigation: upgrade to `>= 2026.3.28` or later.
|
| CVE-2026-34451 |
|
Path Traversal in anthropic (CVE-2026-34451)
path traversal in anthropic (CVE-2026-34451). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30285 |
|
Path Traversal in zora (CVE-2026-30285)
path traversal in zora (CVE-2026-30285). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30290 |
|
Path Traversal in intouchapp (CVE-2026-30290)
path traversal in intouchapp (CVE-2026-30290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30279 |
|
Path Traversal in c (CVE-2026-30279)
path traversal in c (CVE-2026-30279). Successful exploitation can lead to full system takeover.
|