Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-52349 |
|
Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12701 |
|
Path Traversal in path-traversal (CVE-2026-12701)
path traversal in path-traversal (CVE-2026-12701). Data can be tampered with by attackers.
|
| CVE-2026-54910 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
|
| CVE-2026-16219 |
|
Path Traversal in path-traversal (CVE-2026-16219)
path traversal in path-traversal (CVE-2026-16219). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15631 |
|
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
|
| CVE-2026-16088 |
|
Path Traversal in path-traversal (CVE-2026-16088)
path traversal in path-traversal (CVE-2026-16088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47871 |
|
Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-8859 |
|
Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15415 |
|
Vulnerability in Amazon aws (CVE-2026-15415)
vulnerability in Amazon aws (CVE-2026-15415). Data can be tampered with by attackers.
|
| CVE-2026-15343 |
|
Path Traversal in path-traversal (CVE-2026-15343)
path traversal in path-traversal (CVE-2026-15343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15457 |
|
Path Traversal in wordpress (CVE-2026-15457)
path traversal in wordpress (CVE-2026-15457). Confidential information can be exposed externally.
|
| CVE-2026-15160 |
|
Path Traversal in wordpress (CVE-2026-15160)
path traversal in wordpress (CVE-2026-15160). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39359 |
|
Path Traversal in path-traversal (CVE-2026-39359)
path traversal in path-traversal (CVE-2026-39359). Confidential information can be exposed externally.
|
| CVE-2024-32386 |
|
Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
|
| CVE-2026-46336 |
|
Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
|
| CVE-2026-13103 |
|
Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
|
| CVE-2025-45870 |
|
Path Traversal in path-traversal (CVE-2025-45870)
path traversal in path-traversal (CVE-2025-45870). Confidential information can be exposed externally.
|
| CVE-2026-59864 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864). Risk of unauthorized operations or information disclosure. Exploitable via ``static_template.file``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-12979 |
|
Vulnerability in wordpress (CVE-2026-12979)
vulnerability in wordpress (CVE-2026-12979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45533 |
|
Path Traversal in path-traversal (CVE-2026-45533)
path traversal in path-traversal (CVE-2026-45533). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45419 |
|
Path Traversal in path-traversal (CVE-2026-45419)
path traversal in path-traversal (CVE-2026-45419). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12997 |
|
Path Traversal in wordpress (CVE-2026-12997)
path traversal in wordpress (CVE-2026-12997). Confidential information can be exposed externally.
|
| CVE-2026-20297 |
|
Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.
|
| CVE-2026-20146 |
|
Path Traversal in Cisco path-traversal (CVE-2026-20146)
path traversal in Cisco path-traversal (CVE-2026-20146). Confidential information can be exposed externally.
|
| CVE-2026-43637 |
|
Path Traversal in path-traversal (CVE-2026-43637)
path traversal in path-traversal (CVE-2026-43637). Data can be tampered with by attackers.
|
| CVE-2026-61873 |
|
Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
|
| CVE-2026-61446 |
|
Code Injection in path-traversal (CVE-2026-61446)
code injection in path-traversal (CVE-2026-61446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15751 |
|
Path Traversal in path-traversal (CVE-2026-15751)
path traversal in path-traversal (CVE-2026-15751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48338 |
|
Path Traversal in path-traversal (CVE-2026-48338)
path traversal in path-traversal (CVE-2026-48338). Confidential information can be exposed externally.
|
| CVE-2026-15749 |
|
Path Traversal in path-traversal (CVE-2026-15749)
path traversal in path-traversal (CVE-2026-15749). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48350 |
|
Path Traversal in path-traversal (CVE-2026-48350)
path traversal in path-traversal (CVE-2026-48350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48310 |
|
Path Traversal in path-traversal (CVE-2026-48310)
path traversal in path-traversal (CVE-2026-48310). Confidential information can be exposed externally.
|
| CVE-2026-48319 |
|
Path Traversal in path-traversal (CVE-2026-48319)
path traversal in path-traversal (CVE-2026-48319). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48318 |
|
Path Traversal in path-traversal (CVE-2026-48318)
path traversal in path-traversal (CVE-2026-48318). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50454 |
|
Vulnerability in path-traversal (CVE-2026-50454)
vulnerability in path-traversal (CVE-2026-50454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50426 |
|
Vulnerability in path-traversal (CVE-2026-50426)
vulnerability in path-traversal (CVE-2026-50426). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56196 |
|
Vulnerability in path-traversal (CVE-2026-56196)
vulnerability in path-traversal (CVE-2026-56196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50663 |
|
Vulnerability in path-traversal (CVE-2026-50663)
vulnerability in path-traversal (CVE-2026-50663). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45496 |
|
Path Traversal in path-traversal (CVE-2026-45496)
path traversal in path-traversal (CVE-2026-45496). Confidential information can be exposed externally.
|
| CVE-2026-40400 |
|
Vulnerability in path-traversal (CVE-2026-40400)
vulnerability in path-traversal (CVE-2026-40400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15700 |
|
Path Traversal in path-traversal (CVE-2026-15700)
path traversal in path-traversal (CVE-2026-15700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9108 |
|
Path Traversal in path-traversal (CVE-2026-9108)
path traversal in path-traversal (CVE-2026-9108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59839 |
|
Path Traversal in path-traversal (CVE-2026-59839)
path traversal in path-traversal (CVE-2026-59839). Data can be tampered with by attackers.
|
| CVE-2026-11944 |
|
Path Traversal in path-traversal (CVE-2026-11944)
path traversal in path-traversal (CVE-2026-11944). Confidential information can be exposed externally.
|
| CVE-2026-11917 |
|
Path Traversal in path-traversal (CVE-2026-11917)
path traversal in path-traversal (CVE-2026-11917). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60114 |
|
Path Traversal in path-traversal (CVE-2026-60114)
path traversal in path-traversal (CVE-2026-60114). Data can be tampered with by attackers.
|
| CVE-2026-14903 |
|
Path Traversal in path-traversal (CVE-2026-14903)
path traversal in path-traversal (CVE-2026-14903). Confidential information can be exposed externally.
|
| CVE-2026-15265 |
|
Path Traversal in c (CVE-2026-15265)
path traversal in c (CVE-2026-15265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49488 |
|
Path Traversal in apache (CVE-2026-49488)
path traversal in apache (CVE-2026-49488). Confidential information can be exposed externally.
|
| CVE-2026-12482 |
|
Path Traversal in keras (CVE-2026-12482)
path traversal in keras (CVE-2026-12482). Risk of unauthorized operations or information disclosure. Exploitable via ``filter_safe_tarinfos``. Mitigation: upgrade to `3.15.0` or later.
|