Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-22 Clear
ID Title
CVE-2026-5436 Path Traversal in wordpress (CVE-2026-5436)
path traversal in wordpress (CVE-2026-5436). Successful exploitation can lead to full system takeover.
CVE-2026-39844 Path Traversal in zauberzeug (CVE-2026-39844)
path traversal in zauberzeug (CVE-2026-39844). Data can be tampered with by attackers. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-39859 Path Traversal in liquidjs (CVE-2026-39859)
path traversal in liquidjs (CVE-2026-39859). Confidential information can be exposed externally. Mitigation: upgrade to `10.25.3` or later.
CVE-2026-33466 Path Traversal in path-traversal (CVE-2026-33466)
path traversal in path-traversal (CVE-2026-33466). Successful exploitation can lead to full system takeover.
CVE-2026-39406 Path Traversal in hono (CVE-2026-39406)
path traversal in hono (CVE-2026-39406). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.13` or later.
CVE-2026-39407 Path Traversal in hono (CVE-2026-39407)
path traversal in hono (CVE-2026-39407). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.12` or later.
CVE-2026-39408 Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
CVE-2026-3243 The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
CVE-2026-39847 Path Traversal in emmett (CVE-2026-39847)
path traversal in emmett (CVE-2026-39847). Confidential information can be exposed externally. Mitigation: upgrade to `2.8.1` or later.
CVE-2026-39369 Path Traversal in WWBN/AVideo (CVE-2026-39369)
path traversal in WWBN/AVideo (CVE-2026-39369). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoderReceiveImage.json.php`.
CVE-2026-34079 Path Traversal in flatpak (CVE-2026-34079)
path traversal in flatpak (CVE-2026-34079). Data can be tampered with by attackers. Mitigation: upgrade to `1.16.4` or later.
CVE-2026-34371 Path Traversal in librechat (CVE-2026-34371)
path traversal in librechat (CVE-2026-34371). Data can be tampered with by attackers. Mitigation: upgrade to `0.8.4` or later.
CVE-2026-39365 Path Traversal in vitejs (CVE-2026-39365)
path traversal in vitejs (CVE-2026-39365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.4.2` or later.
CVE-2026-39345 Path Traversal in orangehrm (CVE-2026-39345)
path traversal in orangehrm (CVE-2026-39345). Confidential information can be exposed externally. Mitigation: upgrade to `5.8.1` or later.
CVE-2026-35454 Path Traversal in github.com/coder/code-marketplace (CVE-2026-35454)
path traversal in github.com/coder/code-marketplace (CVE-2026-35454). Data can be tampered with by attackers. Exploitable via ``ExtractZip``. Mitigation: upgrade to `1.2.3-0.20260402184705-988440dee05f` or later.
CVE-2026-35471 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35392 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35392)
path traversal in github.com/patrickhener/goshs (CVE-2026-35392). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35393 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35393)
path traversal in github.com/patrickhener/goshs (CVE-2026-35393). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35177 Path Traversal in c (CVE-2026-35177)
path traversal in c (CVE-2026-35177). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0280` or later.
CVE-2026-35174 Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
CVE-2026-5597 Path Traversal in path-traversal (CVE-2026-5597)
path traversal in path-traversal (CVE-2026-5597). Risk of unauthorized operations or information disclosure.
CVE-2019-25687 Path Traversal in wisdom (CVE-2019-25687)
path traversal in wisdom (CVE-2019-25687). Successful exploitation can lead to full system takeover.
CVE-2019-25671 Path Traversal in c (CVE-2019-25671)
path traversal in c (CVE-2019-25671). Successful exploitation can lead to full system takeover.
CVE-2026-5595 Path Traversal in path-traversal (CVE-2026-5595)
path traversal in path-traversal (CVE-2026-5595). Risk of unauthorized operations or information disclosure.
CVE-2026-5535 Path Traversal in path-traversal (CVE-2026-5535)
path traversal in path-traversal (CVE-2026-5535). Risk of unauthorized operations or information disclosure.
CVE-2026-3666 Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
CVE-2026-34607 Path Traversal in path-traversal (CVE-2026-34607)
path traversal in path-traversal (CVE-2026-34607). Successful exploitation can lead to full system takeover.
CVE-2026-34978 Path Traversal in path-traversal (CVE-2026-34978)
path traversal in path-traversal (CVE-2026-34978). Risk of unauthorized operations or information disclosure.
CVE-2026-26058 Path Traversal in path-traversal (CVE-2026-26058)
path traversal in path-traversal (CVE-2026-26058). Confidential information can be exposed externally.
CVE-2026-22661 Path Traversal in path-traversal (CVE-2026-22661)
path traversal in path-traversal (CVE-2026-22661). Confidential information can be exposed externally.
CVE-2026-28373 Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
CVE-2026-35214 Path Traversal in path-traversal (CVE-2026-35214)
path traversal in path-traversal (CVE-2026-35214). Data can be tampered with by attackers. Exploitable via `POST /api/plugin/upload`.
CVE-2025-59711 Path Traversal in path-traversal (CVE-2025-59711)
path traversal in path-traversal (CVE-2025-59711). Confidential information can be exposed externally.
CVE-2025-59709 Path Traversal in c (CVE-2025-59709)
path traversal in c (CVE-2025-59709). Confidential information can be exposed externally.
CVE-2026-4350 The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
CVE-2026-34745 Path Traversal in shaneisrael (CVE-2026-34745)
path traversal in shaneisrael (CVE-2026-34745). Data can be tampered with by attackers.
CVE-2026-34726 Path Traversal in path-traversal (CVE-2026-34726)
path traversal in path-traversal (CVE-2026-34726). Risk of unauthorized operations or information disclosure.
CVE-2026-34730 Path Traversal in copier-org (CVE-2026-34730)
path traversal in copier-org (CVE-2026-34730). Confidential information can be exposed externally.
CVE-2026-34591 Path Traversal in python-poetry (CVE-2026-34591)
path traversal in python-poetry (CVE-2026-34591). Data can be tampered with by attackers.
CVE-2026-34522 Path Traversal in path-traversal (CVE-2026-34522)
path traversal in path-traversal (CVE-2026-34522). Data can be tampered with by attackers.
CVE-2026-34523 Path Traversal in path-traversal (CVE-2026-34523)
path traversal in path-traversal (CVE-2026-34523). Risk of unauthorized operations or information disclosure.
CVE-2026-34524 Path Traversal in path-traversal (CVE-2026-34524)
path traversal in path-traversal (CVE-2026-34524). Confidential information can be exposed externally.
CVE-2026-5344 Path Traversal in path-traversal (CVE-2026-5344)
path traversal in path-traversal (CVE-2026-5344). Risk of unauthorized operations or information disclosure.
CVE-2026-3987 Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
CVE-2026-27489 Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
CVE-2026-41363 Path Traversal in openclaw (CVE-2026-41363)
path traversal in openclaw (CVE-2026-41363). Confidential information can be exposed externally. Mitigation: upgrade to `>= 2026.3.28` or later.
CVE-2026-34451 Path Traversal in anthropic (CVE-2026-34451)
path traversal in anthropic (CVE-2026-34451). Risk of unauthorized operations or information disclosure.
CVE-2026-30285 Path Traversal in zora (CVE-2026-30285)
path traversal in zora (CVE-2026-30285). Successful exploitation can lead to full system takeover.
CVE-2026-30290 Path Traversal in intouchapp (CVE-2026-30290)
path traversal in intouchapp (CVE-2026-30290). Successful exploitation can lead to full system takeover.
CVE-2026-30279 Path Traversal in c (CVE-2026-30279)
path traversal in c (CVE-2026-30279). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →