Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified CRITICAL 9.9
CVE-2026-61445

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation a…

Mitigation only
Fix from $2,300 2026-07-11
Unclassified MEDIUM 5.5
CVE-2026-60088

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. A…

Patch available
Fix from $1,600 2026-07-11
Unclassified HIGH 7.5
CVE-2026-9282

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources functio…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-11426

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to th…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.6
CVE-2026-55852

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members w…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.1
CVE-2026-41482

Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure loc…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.9
CVE-2026-42219

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was possible due to lack of hard…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 8.2
CVE-2026-58499

EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint becau…

Patch available
Fix from $1,950 2026-07-10
Snipe It MEDIUM 6.5
CVE-2026-55469

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path t…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2025-70796

An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/24 …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.7
CVE-2026-61432

PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastCont…

Patch available
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.5
CVE-2026-60089

PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an A…

Patch available
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.5
CVE-2026-61431

PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .prais…

Patch available
Fix from $1,600 2026-07-10
Unisphere For Powermax MEDIUM 6.5
CVE-2026-54468

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access c…

Fix: 10.3.0.7+
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-40005

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files a…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.5
CVE-2026-13347

The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrappe…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-15331

A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_package of the file agent/skills/…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 8.7
CVE-2026-50180

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_valid…

Patch available
Fix from $1,950 2026-07-10
Unclassified HIGH 7.1
CVE-2026-50181

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool…

Patch available
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-54760

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation,…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.7
CVE-2026-59832

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/s…

Patch available
Fix from $1,950 2026-07-09
Decompress MEDIUM 6.2
CVE-2026-39245

decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir functi…

Fix: after 4.2.1
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-59149

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath i…

Patch available
Fix from $1,600 2026-07-09
Unclassified HIGH 8.8
CVE-2026-13492

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient valid…

Patch available
Fix from $1,950 2026-07-09
Open Webui HIGH 7.7
CVE-2026-59221

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_…

Patch available
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-15204

A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportO…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.1
CVE-2026-14372

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file d…

Mitigation only
Fix from $1,950 2026-07-09
Bosh Cli CRITICAL 9.1
CVE-2026-47826

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.…

Fix: 7.10.4+
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15138

A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_t…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.8
CVE-2026-55878

Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs file…

Patch available
Fix from $1,950 2026-07-08