Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-22 Clear
ID Title
CVE-2026-18899 Path Traversal in path-traversal (CVE-2026-18899)
path traversal in path-traversal (CVE-2026-18899). Confidential information can be exposed externally.
CVE-2026-82286 Path Traversal in CVE-2026-82286 (CVE-2026-82286)
path traversal in CVE-2026-82286 (CVE-2026-82286). Data can be tampered with by attackers. Exploitable via `POST /crawl`.
CVE-2026-82275 Path Traversal in path-traversal (CVE-2026-82275)
path traversal in path-traversal (CVE-2026-82275). Confidential information can be exposed externally.
CVE-2026-55552 Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
CVE-2026-82253 Path Traversal in path-traversal (CVE-2026-82253)
path traversal in path-traversal (CVE-2026-82253). Confidential information can be exposed externally.
CVE-2026-82251 Path Traversal in path-traversal (CVE-2026-82251)
path traversal in path-traversal (CVE-2026-82251). Confidential information can be exposed externally.
CVE-2026-54083 Path Traversal in c (CVE-2026-54083)
path traversal in c (CVE-2026-54083). Data can be tampered with by attackers.
CVE-2026-81730 Path Traversal in CVE-2026-81730 (CVE-2026-81730)
path traversal in CVE-2026-81730 (CVE-2026-81730). Data can be tampered with by attackers.
CVE-2026-76639 Path Traversal in path-traversal (CVE-2026-76639)
path traversal in path-traversal (CVE-2026-76639). Successful exploitation can lead to full system takeover.
CVE-2026-81491 Path Traversal in path-traversal (CVE-2026-81491)
path traversal in path-traversal (CVE-2026-81491). Risk of unauthorized operations or information disclosure.
CVE-2026-75333 Path Traversal in path-traversal (CVE-2026-75333)
path traversal in path-traversal (CVE-2026-75333). Confidential information can be exposed externally.
CVE-2026-75328 Path Traversal in CVE-2026-75328 (CVE-2026-75328)
path traversal in CVE-2026-75328 (CVE-2026-75328). Confidential information can be exposed externally.
CVE-2026-61792 Path Traversal in path-traversal (CVE-2026-61792)
path traversal in path-traversal (CVE-2026-61792). Confidential information can be exposed externally.
CVE-2026-36851 Path Traversal in path-traversal (CVE-2026-36851)
path traversal in path-traversal (CVE-2026-36851). Confidential information can be exposed externally.
CVE-2026-54550 Path Traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550)
path traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550). Data can be tampered with by attackers. Exploitable via ``targetPath``.
CVE-2026-15990 Path Traversal in wordpress (CVE-2026-15990)
path traversal in wordpress (CVE-2026-15990). Confidential information can be exposed externally.
CVE-2026-75797 Path Traversal in wordpress (CVE-2026-75797)
path traversal in wordpress (CVE-2026-75797). Confidential information can be exposed externally.
CVE-2026-57171 Path Traversal in CVE-2026-57171 (CVE-2026-57171)
path traversal in CVE-2026-57171 (CVE-2026-57171). Data can be tampered with by attackers.
CVE-2026-65092 Path Traversal in path-traversal (CVE-2026-65092)
path traversal in path-traversal (CVE-2026-65092). Confidential information can be exposed externally.
CVE-2026-79622 Path Traversal in path-traversal (CVE-2026-79622)
path traversal in path-traversal (CVE-2026-79622). Risk of unauthorized operations or information disclosure.
CVE-2026-57863 Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
CVE-2026-55527 Path Traversal in praisonaiagents (CVE-2026-55527)
path traversal in praisonaiagents (CVE-2026-55527). Data can be tampered with by attackers. Exploitable via `POST /jobs`. Mitigation: upgrade to `1.6.58` or later.
CVE-2026-55540 Path Traversal in PraisonAI (CVE-2026-55540)
path traversal in PraisonAI (CVE-2026-55540). Confidential information can be exposed externally. Exploitable via ``praisonai.code``. Mitigation: upgrade to `4.6.58` or later.
CVE-2026-68062 SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
CVE-2026-78677 GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
CVE-2026-72695 Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
CVE-2026-34968 Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
CVE-2026-78284 Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
CVE-2026-71364 Path Traversal in path-traversal (CVE-2026-71364)
path traversal in path-traversal (CVE-2026-71364). Successful exploitation can lead to full system takeover.
CVE-2026-76844 Path Traversal in CVE-2026-76844 (CVE-2026-76844)
path traversal in CVE-2026-76844 (CVE-2026-76844). Confidential information can be exposed externally. Exploitable via `GET /assets../.env`.
CVE-2026-76842 Path Traversal in CVE-2026-76842 (CVE-2026-76842)
path traversal in CVE-2026-76842 (CVE-2026-76842). Confidential information can be exposed externally.
CVE-2026-28167 Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
CVE-2026-32477 Path Traversal in CVE-2026-32477 (CVE-2026-32477)
path traversal in CVE-2026-32477 (CVE-2026-32477). Risk of unauthorized operations or information disclosure.
CVE-2026-28171 Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
CVE-2026-10053 Path Traversal in path-traversal (CVE-2026-10053)
path traversal in path-traversal (CVE-2026-10053). Successful exploitation can lead to full system takeover.
CVE-2026-63312 Path Traversal in CVE-2026-63312 (CVE-2026-63312)
path traversal in CVE-2026-63312 (CVE-2026-63312). Confidential information can be exposed externally.
CVE-2026-62384 Path Traversal in CVE-2026-62384 (CVE-2026-62384)
path traversal in CVE-2026-62384 (CVE-2026-62384). Confidential information can be exposed externally.
CVE-2026-60084 Path Traversal in CVE-2026-60084 (CVE-2026-60084)
path traversal in CVE-2026-60084 (CVE-2026-60084). Data can be tampered with by attackers.
CVE-2026-64679 Path Traversal in github.com/runatlantis/atlantis (CVE-2026-64679)
path traversal in github.com/runatlantis/atlantis (CVE-2026-64679). Data can be tampered with by attackers. Exploitable via ``workspace``. Mitigation: upgrade to `0.45.0` or later.
CVE-2026-62677 Path Traversal in CVE-2026-62677 (CVE-2026-62677)
path traversal in CVE-2026-62677 (CVE-2026-62677). Successful exploitation can lead to full system takeover.
CVE-2026-49114 Path Traversal in CVE-2026-49114 (CVE-2026-49114)
path traversal in CVE-2026-49114 (CVE-2026-49114). Data can be tampered with by attackers. Mitigation: upgrade to `1.21.0` or later.
CVE-2026-77814 Path Traversal in CVE-2026-77814 (CVE-2026-77814)
path traversal in CVE-2026-77814 (CVE-2026-77814). Confidential information can be exposed externally.
CVE-2026-73040 Path Traversal in CVE-2026-73040 (CVE-2026-73040)
path traversal in CVE-2026-73040 (CVE-2026-73040). Successful exploitation can lead to full system takeover.
CVE-2026-18274 Path Traversal in path-traversal (CVE-2026-18274)
path traversal in path-traversal (CVE-2026-18274). Successful exploitation can lead to full system takeover.
CVE-2026-63490 Path Traversal in CVE-2026-63490 (CVE-2026-63490)
path traversal in CVE-2026-63490 (CVE-2026-63490). Confidential information can be exposed externally.
CVE-2026-76832 Path Traversal in path-traversal (CVE-2026-76832)
path traversal in path-traversal (CVE-2026-76832). Successful exploitation can lead to full system takeover.
CVE-2026-76357 Path Traversal in splunk (CVE-2026-76357)
path traversal in splunk (CVE-2026-76357). Risk of unauthorized operations or information disclosure.
CVE-2026-62680 Path Traversal in CVE-2026-62680 (CVE-2026-62680)
path traversal in CVE-2026-62680 (CVE-2026-62680). Confidential information can be exposed externally.
CVE-2026-15061 Path Traversal in path-traversal (CVE-2026-15061)
path traversal in path-traversal (CVE-2026-15061). Data can be tampered with by attackers.
CVE-2026-76222 Path Traversal in CVE-2026-76222 (CVE-2026-76222)
path traversal in CVE-2026-76222 (CVE-2026-76222). Data can be tampered with by attackers.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →