Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.7
CVE-2026-60027

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …

No fix yet
Fix from $1,950 2026-07-20
Network Ai HIGH 7.1
CVE-2026-58484

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manife…

Fix: 5.12.2+
Fix from $1,950 2026-07-20
Network Ai MEDIUM 6.1
CVE-2026-58413

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup…

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Network Ai MEDIUM 5.5
CVE-2026-58414

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using …

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Network Ai MEDIUM 6.5
CVE-2026-58481

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured s…

Fix: 5.12.2+
Fix from $1,600 2026-07-20
Whatsapp Mcp Server HIGH 7.1
CVE-2026-46555

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1…

Fix available
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32820

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Mailpit HIGH 8.2
CVE-2026-45711

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads …

Fix: 1.30.0+
Fix from $1,950 2026-07-20
Unclassified HIGH 7.7
CVE-2026-54910

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/sub…

Patch available
Fix from $1,950 2026-07-20
Unclassified HIGH 7.8
CVE-2026-52349

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary …

Patch available
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.0
CVE-2026-12701

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but…

No fix yet
Fix from $2,300 2026-07-20
Surrealdb HIGH 7.7
CVE-2026-63739

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or O…

Fix: 3.1.5+
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-12898

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16219

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.ph…

No fix yet
Fix from $1,600 2026-07-19
Fastify\/http Proxy CRITICAL 10.0
CVE-2026-15631

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the confi…

Fix: 11.6.0+
Fix from $2,300 2026-07-18
Unclassified HIGH 8.8
CVE-2026-47871

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to …

Mitigation only
Fix from $1,950 2026-07-18
Unclassified MEDIUM 5.3
CVE-2026-48049

@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured…

Patch available
Fix from $1,600 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8859

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow HIGH 8.1
CVE-2026-7872

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow HIGH 8.8
CVE-2026-7667

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Unclassified HIGH 7.1
CVE-2026-50163

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relat…

Patch available
Fix from $1,950 2026-07-17
Asyncssh HIGH 7.5
CVE-2026-45309

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame…

Fix: 2.23.0+
Fix from $1,950 2026-07-17
Unclassified HIGH 8.6
CVE-2026-15343

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updat…

No fix yet
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62229

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute ac…

Fix: 2026.5.18+
Fix from $1,950 2026-07-17
Wazuh HIGH 7.5
CVE-2026-39359

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.1…

Fix: 4.10.4 / 4.14.5+
Fix from $1,950 2026-07-17
Unclassified HIGH 8.8
CVE-2026-44177

Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user…

No fix yet
Fix from $1,950 2026-07-16
Docling Core HIGH 8.6
CVE-2026-44023

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.…

Fix: 2.74.1+
Fix from $1,950 2026-07-16
Unclassified HIGH 7.3
CVE-2024-32386

Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive in…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.7
CVE-2026-55629

Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req…

Patch available
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.9
CVE-2026-53535

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a …

Patch available
Fix from $1,600 2026-07-16