Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Buildkit HIGH 7.5
CVE-2026-15791

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used …

Fix: 0.31.2+
Fix from $1,950 2026-07-21
Unclassified HIGH 8.4
CVE-2026-64824

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to ar…

Mitigation only
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.3
CVE-2026-64825

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any dir…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 8.7
CVE-2026-47394

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original adviso…

No fix yet
Fix from $1,950 2026-07-21
Sparkle MEDIUM 6.1
CVE-2026-47121

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents con…

Fix: 2.9.2+
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.9
CVE-2026-13693

The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a no…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.5
CVE-2026-47144

Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-con…

No fix yet
Fix from $1,600 2026-07-20
Mina Sshd HIGH 7.5
CVE-2026-56452

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The impleme…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Mina Sshd HIGH 7.1
CVE-2026-56623

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git s…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-60027

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …

No fix yet
Fix from $1,950 2026-07-20
Network Ai HIGH 7.1
CVE-2026-58484

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manife…

Fix: 5.12.2+
Fix from $1,950 2026-07-20
Network Ai MEDIUM 6.1
CVE-2026-58413

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup…

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Network Ai MEDIUM 5.5
CVE-2026-58414

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using …

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Network Ai MEDIUM 6.5
CVE-2026-58481

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured s…

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Whatsapp Mcp Server HIGH 7.1
CVE-2026-46555

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32820

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Mailpit HIGH 8.2
CVE-2026-45711

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads …

Fix: 1.30.0+
Fix from $1,950 2026-07-20
Unclassified HIGH 7.7
CVE-2026-54910

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/sub…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.8
CVE-2026-52349

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary …

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.0
CVE-2026-12701

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but…

No fix yet
Fix from $2,300 2026-07-20
Surrealdb HIGH 7.7
CVE-2026-63739

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or O…

Fix: 3.1.5+
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-12898

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16219

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.ph…

No fix yet
Fix from $1,600 2026-07-19
Fastify\/http Proxy CRITICAL 10.0
CVE-2026-15631

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the confi…

Fix: 11.6.0+
Fix from $2,300 2026-07-18
Unclassified HIGH 8.8
CVE-2026-47871

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to …

Mitigation only
Fix from $1,950 2026-07-18
Unclassified MEDIUM 5.3
CVE-2026-48049

@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured…

No fix yet
Fix from $1,600 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8859

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow HIGH 8.1
CVE-2026-7872

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow HIGH 8.8
CVE-2026-7667

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Unclassified HIGH 7.1
CVE-2026-50163

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relat…

No fix yet
Fix from $1,950 2026-07-17