Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Standalone Report Designer CRITICAL 9.8
CVE-2026-65689

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that all…

Fix: 14.1.12+
Fix from $2,300 2026-07-23
Standalone Report Designer HIGH 8.8
CVE-2026-65690

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that all…

Fix: 14.1.12+
Fix from $1,950 2026-07-23
Standalone Report Designer CRITICAL 9.8
CVE-2026-65687

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows…

Fix: 14.1.12+
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65607

SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serv…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.7
CVE-2026-59542

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-59555

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.1
CVE-2026-57696

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-57716

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65754

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the s…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-64872

Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directo…

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-65431

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.2
CVE-2026-65712

Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site …

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-65713

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-16078

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including…

No fix yet
Fix from $1,600 2026-07-23
Fastify Static HIGH 7.5
CVE-2026-15074

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This …

Fix: 10.1.1+
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16653

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.8
CVE-2026-14985

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to…

No fix yet
Fix from $1,950 2026-07-22
Telerik Ui For Asp.net Ajax HIGH 8.1
CVE-2026-13186

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploite…

Fix: 2026.2.708+
Fix from $1,950 2026-07-22
Traefik MEDIUM 5.3
CVE-2026-65600

Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathReg…

Fix: 2.11.52 / 3.6.23+
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.6
CVE-2026-44192

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to ma…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 8.4
CVE-2026-56844

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain roo…

No fix yet
Fix from $1,950 2026-07-22
Unclassified CRITICAL 9.1
CVE-2026-47731

The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to …

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 7.5
CVE-2026-30633

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.8
CVE-2026-50757

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.5
CVE-2026-30632

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

No fix yet
Fix from $1,950 2026-07-21
Arubaos Cx HIGH 7.2
CVE-2026-63454

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary fi…

Fix: after 10.18.0001
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.9
CVE-2026-47425

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_c…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.1
CVE-2026-47397

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled c…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.7
CVE-2026-15724

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal …

No fix yet
Fix from $1,950 2026-07-21
Buildkit HIGH 7.5
CVE-2026-15789

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The cli…

Fix: 0.31.2+
Fix from $1,950 2026-07-21