Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: path-traversal Clear
ID Title
CVE-2026-52349 Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
CVE-2026-12701 Path Traversal in path-traversal (CVE-2026-12701)
path traversal in path-traversal (CVE-2026-12701). Data can be tampered with by attackers.
CVE-2026-54910 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
CVE-2026-16219 Path Traversal in path-traversal (CVE-2026-16219)
path traversal in path-traversal (CVE-2026-16219). Risk of unauthorized operations or information disclosure.
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-16088 Path Traversal in path-traversal (CVE-2026-16088)
path traversal in path-traversal (CVE-2026-16088). Risk of unauthorized operations or information disclosure.
CVE-2026-47871 Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-8859 Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
CVE-2026-15415 Vulnerability in Amazon aws (CVE-2026-15415)
vulnerability in Amazon aws (CVE-2026-15415). Data can be tampered with by attackers.
CVE-2026-15343 Path Traversal in path-traversal (CVE-2026-15343)
path traversal in path-traversal (CVE-2026-15343). Risk of unauthorized operations or information disclosure.
CVE-2026-15457 Path Traversal in wordpress (CVE-2026-15457)
path traversal in wordpress (CVE-2026-15457). Confidential information can be exposed externally.
CVE-2026-15160 Path Traversal in wordpress (CVE-2026-15160)
path traversal in wordpress (CVE-2026-15160). Risk of unauthorized operations or information disclosure.
CVE-2026-39359 Path Traversal in path-traversal (CVE-2026-39359)
path traversal in path-traversal (CVE-2026-39359). Confidential information can be exposed externally.
CVE-2024-32386 Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
CVE-2026-46336 Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
CVE-2026-13103 Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
CVE-2025-45870 Path Traversal in path-traversal (CVE-2025-45870)
path traversal in path-traversal (CVE-2025-45870). Confidential information can be exposed externally.
CVE-2026-59864 Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864). Risk of unauthorized operations or information disclosure. Exploitable via ``static_template.file``. Mitigation: upgrade to `1.29.1` or later.
CVE-2026-12979 Vulnerability in wordpress (CVE-2026-12979)
vulnerability in wordpress (CVE-2026-12979). Risk of unauthorized operations or information disclosure.
CVE-2026-45533 Path Traversal in path-traversal (CVE-2026-45533)
path traversal in path-traversal (CVE-2026-45533). Risk of unauthorized operations or information disclosure.
CVE-2026-45419 Path Traversal in path-traversal (CVE-2026-45419)
path traversal in path-traversal (CVE-2026-45419). Risk of unauthorized operations or information disclosure.
CVE-2026-12997 Path Traversal in wordpress (CVE-2026-12997)
path traversal in wordpress (CVE-2026-12997). Confidential information can be exposed externally.
CVE-2026-20297 Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.
CVE-2026-20146 Path Traversal in Cisco path-traversal (CVE-2026-20146)
path traversal in Cisco path-traversal (CVE-2026-20146). Confidential information can be exposed externally.
CVE-2026-43637 Path Traversal in path-traversal (CVE-2026-43637)
path traversal in path-traversal (CVE-2026-43637). Data can be tampered with by attackers.
CVE-2026-61873 Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
CVE-2026-61446 Code Injection in path-traversal (CVE-2026-61446)
code injection in path-traversal (CVE-2026-61446). Successful exploitation can lead to full system takeover.
CVE-2026-15751 Path Traversal in path-traversal (CVE-2026-15751)
path traversal in path-traversal (CVE-2026-15751). Risk of unauthorized operations or information disclosure.
CVE-2026-48338 Path Traversal in path-traversal (CVE-2026-48338)
path traversal in path-traversal (CVE-2026-48338). Confidential information can be exposed externally.
CVE-2026-15749 Path Traversal in path-traversal (CVE-2026-15749)
path traversal in path-traversal (CVE-2026-15749). Risk of unauthorized operations or information disclosure.
CVE-2026-48350 Path Traversal in path-traversal (CVE-2026-48350)
path traversal in path-traversal (CVE-2026-48350). Successful exploitation can lead to full system takeover.
CVE-2026-48310 Path Traversal in path-traversal (CVE-2026-48310)
path traversal in path-traversal (CVE-2026-48310). Confidential information can be exposed externally.
CVE-2026-48319 Path Traversal in path-traversal (CVE-2026-48319)
path traversal in path-traversal (CVE-2026-48319). Successful exploitation can lead to full system takeover.
CVE-2026-48318 Path Traversal in path-traversal (CVE-2026-48318)
path traversal in path-traversal (CVE-2026-48318). Successful exploitation can lead to full system takeover.
CVE-2026-50454 Vulnerability in path-traversal (CVE-2026-50454)
vulnerability in path-traversal (CVE-2026-50454). Successful exploitation can lead to full system takeover.
CVE-2026-50426 Vulnerability in path-traversal (CVE-2026-50426)
vulnerability in path-traversal (CVE-2026-50426). Successful exploitation can lead to full system takeover.
CVE-2026-56196 Vulnerability in path-traversal (CVE-2026-56196)
vulnerability in path-traversal (CVE-2026-56196). Successful exploitation can lead to full system takeover.
CVE-2026-50663 Vulnerability in path-traversal (CVE-2026-50663)
vulnerability in path-traversal (CVE-2026-50663). Successful exploitation can lead to full system takeover.
CVE-2026-45496 Path Traversal in path-traversal (CVE-2026-45496)
path traversal in path-traversal (CVE-2026-45496). Confidential information can be exposed externally.
CVE-2026-40400 Vulnerability in path-traversal (CVE-2026-40400)
vulnerability in path-traversal (CVE-2026-40400). Successful exploitation can lead to full system takeover.
CVE-2026-15700 Path Traversal in path-traversal (CVE-2026-15700)
path traversal in path-traversal (CVE-2026-15700). Risk of unauthorized operations or information disclosure.
CVE-2026-9108 Path Traversal in path-traversal (CVE-2026-9108)
path traversal in path-traversal (CVE-2026-9108). Successful exploitation can lead to full system takeover.
CVE-2026-59839 Path Traversal in path-traversal (CVE-2026-59839)
path traversal in path-traversal (CVE-2026-59839). Data can be tampered with by attackers.
CVE-2026-11944 Path Traversal in path-traversal (CVE-2026-11944)
path traversal in path-traversal (CVE-2026-11944). Confidential information can be exposed externally.
CVE-2026-11917 Path Traversal in path-traversal (CVE-2026-11917)
path traversal in path-traversal (CVE-2026-11917). Risk of unauthorized operations or information disclosure.
CVE-2026-60114 Path Traversal in path-traversal (CVE-2026-60114)
path traversal in path-traversal (CVE-2026-60114). Data can be tampered with by attackers.
CVE-2026-14903 Path Traversal in path-traversal (CVE-2026-14903)
path traversal in path-traversal (CVE-2026-14903). Confidential information can be exposed externally.
CVE-2026-15265 Path Traversal in c (CVE-2026-15265)
path traversal in c (CVE-2026-15265). Successful exploitation can lead to full system takeover.
CVE-2026-49488 Path Traversal in apache (CVE-2026-49488)
path traversal in apache (CVE-2026-49488). Confidential information can be exposed externally.
CVE-2026-12482 Path Traversal in keras (CVE-2026-12482)
path traversal in keras (CVE-2026-12482). Risk of unauthorized operations or information disclosure. Exploitable via ``filter_safe_tarinfos``. Mitigation: upgrade to `3.15.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →