Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.1
CVE-2026-46336

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 unti…

Patch available
Fix from $1,950 2026-07-16
Zrok CRITICAL 9.1
CVE-2026-45568

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an ab…

Fix: 2.0.3+
Fix from $2,300 2026-07-16
Zrok HIGH 7.5
CVE-2026-45576

zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or z…

Fix: 2.0.3+
Fix from $1,950 2026-07-16
Unclassified HIGH 7.3
CVE-2026-13103

A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local au…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2025-45870

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated …

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59864

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59866

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa…

Patch available
Fix from $2,300 2026-07-16
Unclassified HIGH 7.1
CVE-2026-59867

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs …

Patch available
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-53598

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty fron…

Patch available
Fix from $1,950 2026-07-16
Unclassified HIGH 7.0
CVE-2026-59863

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configurat…

Patch available
Fix from $1,950 2026-07-16
Unclassified HIGH 7.1
CVE-2026-52890

Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /att…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 8.5
CVE-2026-45419

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticRes…

Patch available
Fix from $1,950 2026-07-15
Unclassified HIGH 8.3
CVE-2026-45533

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequence…

Patch available
Fix from $1,950 2026-07-15
Ivy MEDIUM 5.4
CVE-2026-26032

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repa…

Fix: 2.6.0+
Fix from $1,600 2026-07-15
Unclassified HIGH 7.5
CVE-2026-12997

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_file…

Mitigation only
Fix from $1,950 2026-07-15
Splunk HIGH 7.2
CVE-2026-20297

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10…

Fix: 9.3.14 / 9.4.13+
Fix from $1,950 2026-07-15
Identity Services Engine Passive Identity Connector MEDIUM 5.5
CVE-2026-20146

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attac…

Fix: 3.3.0+
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.8
CVE-2026-62843

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 …

Patch available
Fix from $1,600 2026-07-15
Nginx Agent MEDIUM 6.4
CVE-2026-60062

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secur…

Fix: 2.22.2 / 2.46.7+
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.1
CVE-2026-43637

Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache dire…

Patch available
Fix from $2,300 2026-07-15
Unclassified HIGH 8.1
CVE-2026-61443

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containmen…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.4
CVE-2026-56352

n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files fr…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.3
CVE-2026-15751

A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the fil…

Mitigation only
Fix from $1,600 2026-07-14
Rclone HIGH 8.8
CVE-2026-59733

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --…

Fix: 1.74.4+
Fix from $1,950 2026-07-14
Rclone MEDIUM 5.0
CVE-2026-59732

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract…

Fix: 1.74.4+
Fix from $1,600 2026-07-14
Unclassified HIGH 7.0
CVE-2026-54684

jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outs…

Patch available
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-53486

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…

Patch available
Fix from $2,300 2026-07-14
Coldfusion MEDIUM 6.8
CVE-2026-48338

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrar…

Mitigation only
Fix from $1,600 2026-07-14
Coldfusion CRITICAL 9.9
CVE-2026-48318EPSS 23%

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrar…

Mitigation only
Fix from $2,300 2026-07-14
Coldfusion CRITICAL 9.1
CVE-2026-48319EPSS 32%

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitr…

Mitigation only
Fix from $2,300 2026-07-14