Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Fluentd CRITICAL 9.8
CVE-2026-44024

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allo…

Fix: 1.19.3+
Fix from $2,300 2026-07-08
Unclassified HIGH 8.6
CVE-2026-58192

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage…

Patch available
Fix from $1,950 2026-07-08
Unclassified MEDIUM 5.9
CVE-2026-54590

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame…

Patch available
Fix from $1,600 2026-07-08
Unclassified HIGH 8.1
CVE-2026-54591

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame…

Patch available
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.1
CVE-2026-59946

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resol…

Patch available
Fix from $1,600 2026-07-08
Unclassified HIGH 7.0
CVE-2026-59948

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other t…

Patch available
Fix from $1,950 2026-07-08
Litellm MEDIUM 6.5
CVE-2026-59820

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did n…

Fix: 1.83.7+
Fix from $1,600 2026-07-08
Unclassified HIGH 7.5
CVE-2026-55760

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handle…

Patch available
Fix from $1,950 2026-07-08
Mistune MEDIUM 5.9
CVE-2026-59924

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths with…

Fix: 3.3.0+
Fix from $1,600 2026-07-08
Unclassified HIGH 8.8
CVE-2026-53951

Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_setti…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-55668

File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in s…

Patch available
Fix from $1,600 2026-07-08
Unclassified HIGH 7.7
CVE-2026-55874

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header us…

Patch available
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-56273

Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath p…

Mitigation only
Fix from $1,600 2026-07-08
Workspace One Tunnel HIGH 7.8
CVE-2026-22927

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

Fix: 26.03+
Fix from $1,950 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-14500

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to…

No fix yet
Fix from $1,600 2026-07-08
Unclassified HIGH 7.5
CVE-2026-14244

The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' pa…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-14487

The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDi…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 7.2
CVE-2026-55631

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an…

Patch available
Fix from $1,950 2026-07-07
Data Domain Operating System CRITICAL 9.8
CVE-2026-53481

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: 7.13.1.80 / 8.3.1.40+
Fix from $2,300 2026-07-07
Unclassified HIGH 8.8
CVE-2026-42200

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initializatio…

Patch available
Fix from $1,950 2026-07-07
Crawl4ai CRITICAL 9.6
CVE-2026-57571

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w…

Fix: 0.9.0+
Fix from $2,300 2026-07-06
Unclassified HIGH 7.7
CVE-2026-14468

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce th…

Mitigation only
Fix from $1,950 2026-07-06
Arcgis Server HIGH 7.5
CVE-2026-9181

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could e…

Fix: after 12.0
Fix from $1,950 2026-07-06
Unclassified MEDIUM 5.0
CVE-2026-59152

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a serve…

Mitigation only
Fix from $1,600 2026-07-06
Pnpm HIGH 7.1
CVE-2026-59194

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm p…

Fix: 10.34.4 / 11.7.0+
Fix from $1,950 2026-07-06
Pnpm HIGH 8.2
CVE-2026-59195

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those na…

Fix: 10.34.4 / 11.8.0+
Fix from $1,950 2026-07-06
Pnpm HIGH 7.1
CVE-2026-59196

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Tra…

Fix: 10.34.4 / 11.7.0+
Fix from $1,950 2026-07-06
Pydantic Settings MEDIUM 5.3
CVE-2026-58203

pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files i…

Fix: 2.14.2+
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.0
CVE-2026-7185

A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite.…

Mitigation only
Fix from $1,600 2026-07-06
Apache Airflow Providers Google HIGH 8.1
CVE-2026-49297

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket …

Fix: 22.2.1+
Fix from $1,950 2026-07-06