Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.3
CVE-2026-15749

A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/…

Mitigation only
Fix from $1,600 2026-07-14
Animate HIGH 8.6
CVE-2026-48350

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary…

Fix: 23.0.16 / 24.0.14+
Fix from $1,950 2026-07-14
Experience Manager HIGH 8.6
CVE-2026-48310

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could le…

Fix: after 2020.5.0
Fix from $1,950 2026-07-14
Vitest MEDIUM 5.9
CVE-2026-47429

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly fo…

Fix: 3.2.5 / 4.1.0+
Fix from $1,600 2026-07-14
Visual Studio Code MEDIUM 5.5
CVE-2026-45496

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a secu…

Fix: 1.128.1+
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.4
CVE-2026-9108

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The soft…

Mitigation only
Fix from $1,600 2026-07-14
Fortiproxy MEDIUM 5.5
CVE-2026-59839

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0…

Fix: 1.7.3 / 7.4.10+
Fix from $1,600 2026-07-14
Unclassified HIGH 7.7
CVE-2026-15392

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method buil…

Patch available
Fix from $1,950 2026-07-14
Unclassified HIGH 7.2
CVE-2026-11917

A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the…

Mitigation only
Fix from $1,950 2026-07-14
Opensis MEDIUM 6.5
CVE-2026-11944

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that a…

Mitigation only
Fix from $1,600 2026-07-14
Sustainable Irrigation Platform HIGH 7.5
CVE-2026-60114

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore…

Fix: after 5.2.16
Fix from $1,950 2026-07-14
Xtraction MEDIUM 6.5
CVE-2026-14903

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

Fix: 2026.2.1+
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende…

Mitigation only
Fix from $2,300 2026-07-14
Openmeetings MEDIUM 6.5
CVE-2026-49488

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenM…

Fix: 9.1.0+
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.0
CVE-2026-57898

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauth…

Mitigation only
Fix from $2,300 2026-07-14
Keras MEDIUM 6.5
CVE-2026-12482

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` valid…

No fix yet
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15626

A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 8.8
CVE-2026-57856

Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controll…

Patch available
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-49970

Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded fi…

Patch available
Fix from $1,950 2026-07-13
Unclassified HIGH 7.5
CVE-2026-26396

OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-61505

Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain …

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.5
CVE-2026-57815

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Formina…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.6
CVE-2026-57709

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-w…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.9
CVE-2026-57401

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traver…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 8.6
CVE-2026-57389

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traver…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.2
CVE-2026-13014

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrari…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15527

A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/s…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15522

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build…

Patch available
Fix from $1,600 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15521

A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the com…

Mitigation only
Fix from $1,600 2026-07-13
Crawl4ai CRITICAL 9.1
CVE-2026-56260

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path param…

Fix: 0.8.7+
Fix from $2,300 2026-07-12