Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.5
CVE-2026-73973

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/log…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-73974

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.4
CVE-2026-52875

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-52872

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.4
CVE-2026-47699

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafte…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-48796

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to vers…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-50186

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal s…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-53457

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command executio…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-47627

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to de…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 7.1
CVE-2026-74038

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrollin…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-74044

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by s…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-68922

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py u…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75914

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75859

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.8
CVE-2026-63328

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins wit…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-73181

Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-48798

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trus…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-45532

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is tha…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-75855

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, all…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.7
CVE-2026-75842

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users t…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-15585

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-42162

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.5
CVE-2026-67918

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75111

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read ar…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75482

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-75104

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model d…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-54336

JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user wit…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-40506

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.1
CVE-2026-19589

Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead t…

Fix unknown
Fix from $4,900 2026-08-17