CVE-2026-88288
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials
CVSS
6.5
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 10 sept 2026 · Última mod.: 10 sept 2026 · CWE-36
Sin historial EPSS suficiente todavía.
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-820928.8 ALT—
———IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.8hCVE-2026-684879.9 CRÍ—
———Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.10hCVE-2026-696127.8 ALT28.5%
——9Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.2dCVE-2026-688967.8 ALT28.5%
——9Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.2dCVE-2026-476305.5 MED10.5%
——3NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.9dCVE-2026-476066.5 MED40.9%
——12NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.9d