|
2051
|
8.2 |
HIGH
Network
|
-
|
-
|
i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options…
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-41693
|
2026-05-13 00:29 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2052
|
6.5 |
MEDIUM
Network
|
-
|
-
|
i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, i18next-locize-backend interpolates lng, ns, proje…
|
CWE-22 CWE-74
Path Traversal Injection
|
CVE-2026-41885
|
2026-05-13 00:29 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2053
|
7.3 |
HIGH
Network
|
-
|
-
|
D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.
|
CWE-77
Command Injection
|
CVE-2026-36983
|
2026-05-13 00:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2054
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpoint uses String.startsWith() to validate that a resolved file path is within a …
|
CWE-22
Path Traversal
|
CVE-2026-42885
|
2026-05-13 00:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2055
|
- |
|
-
|
-
|
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.js accepts a user-controlled file path without suf…
|
CWE-22
Path Traversal
|
CVE-2026-42888
|
2026-05-13 00:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2056
|
5.3 |
MEDIUM
Network
|
uriparser_project
|
uriparser
|
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
|
CWE-197
Numeric Truncation Error
|
CVE-2026-44927
|
2026-05-13 00:12 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2057
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHan…
|
CWE-22
Path Traversal
|
CVE-2026-38360
|
2026-05-13 00:10 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2058
|
7.4 |
HIGH
Local
|
-
|
-
|
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directo…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-34354
|
2026-05-13 00:10 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2059
|
7.2 |
HIGH
Network
|
-
|
-
|
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
|
CWE-22
Path Traversal
|
CVE-2026-41951
|
2026-05-13 00:10 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2060
|
3.3 |
LOW
Local
|
-
|
-
|
The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation fe…
|
CWE-22
Path Traversal
|
CVE-2026-41530
|
2026-05-13 00:10 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|