Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Mattermost Server MEDIUM 5.5
CVE-2026-7521

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin…

Fix: 10.11.21 / 11.6.6+
Fix from $1,600 2026-07-28
Unclassified HIGH 7.2
CVE-2026-16585

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to in…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-14490

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-17524

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extractio…

No fix yet
Fix from $1,950 2026-07-28
macOS CRITICAL 9.8
CVE-2026-64731

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be a…

Fix: 15.7.8 / 26.6+
Fix from $2,300 2026-07-27
Ipados CRITICAL 9.3
CVE-2026-64740

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10…

Fix: 14.8.8 / 15.7.8+
Fix from $2,300 2026-07-27
macOS HIGH 8.2
CVE-2026-43772

A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
macOS HIGH 7.8
CVE-2026-43749

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS So…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
Ipados HIGH 7.8
CVE-2026-43723

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS …

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
Artifactory HIGH 8.8
CVE-2026-65921

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build arti…

Fix: 7.111.18 / 7.117.25+
Fix from $1,950 2026-07-27
Postcss CRITICAL 9.1
CVE-2026-45623

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.…

Fix: 8.5.12+
Fix from $2,300 2026-07-27
Unclassified HIGH 8.6
CVE-2026-66397

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attacker…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.5
CVE-2026-66050

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.8
CVE-2026-65436

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 8.3
CVE-2026-65878

Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.3
CVE-2026-17514

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.9
CVE-2026-65765

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download action…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-14955

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7…

No fix yet
Fix from $1,600 2026-07-25
Unclassified MEDIUM 5.3
CVE-2026-66004

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitr…

No fix yet
Fix from $1,600 2026-07-24
Datasets MEDIUM 6.5
CVE-2026-66007

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadat…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-16767

A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the componen…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65694

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to r…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-47669

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65919

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoint…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-65700

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65701

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.6
CVE-2026-65702

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated re…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65698

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrar…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.8
CVE-2026-65695

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filen…

No fix yet
Fix from $1,600 2026-07-23
Standalone Report Designer CRITICAL 9.8
CVE-2026-65688

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allow…

Fix: 14.1.12+
Fix from $2,300 2026-07-23