Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.1
CVE-2026-59510

AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.g…

Patch available
Fix from $1,950 2026-07-05
Unclassified HIGH 7.3
CVE-2026-14635

A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects…

Patch available
Fix from $1,950 2026-07-04
Unclassified MEDIUM 5.4
CVE-2026-14636

A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the functio…

Patch available
Fix from $1,600 2026-07-04
Unclassified MEDIUM 5.3
CVE-2026-14628

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base…

Mitigation only
Fix from $1,600 2026-07-04
Unclassified MEDIUM 5.3
CVE-2026-28705

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially craf…

Patch available
Fix from $1,600 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47896

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47897

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-9725

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified HIGH 7.5
CVE-2026-14352

The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-14327

The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter pa…

Mitigation only
Fix from $1,950 2026-07-03
Fireware HIGH 7.2
CVE-2026-13054

A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on…

Fix: 12.12.1 / 2026.2.1+
Fix from $1,950 2026-07-03
Unclassified HIGH 7.7
CVE-2026-58460

react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside th…

Patch available
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.4
CVE-2026-52830

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se…

No fix yet
Fix from $2,300 2026-07-02
Unclassified HIGH 7.5
CVE-2026-58467

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.1
CVE-2026-7311

The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati…

Mitigation only
Fix from $1,950 2026-07-02
Unifi Access HIGH 8.6
CVE-2026-55117

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the ho…

Fix: 4.2.29+
Fix from $1,950 2026-07-02
Unifi Network Application HIGH 8.7
CVE-2026-54406

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi…

Fix: 10.4.57+
Fix from $1,950 2026-07-02
Protect Floodlight Firmware HIGH 7.5
CVE-2026-55111

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files o…

Fix: 1.13.6+
Fix from $1,950 2026-07-02
Unifi Os Server HIGH 8.6
CVE-2026-54403

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authent…

Fix: after 5.1.15
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-13369

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and inclu…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-9145

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() functio…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.5
CVE-2026-13251

The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This mak…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.4
CVE-2026-14439

A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence …

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-58451

Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from th…

Patch available
Fix from $1,600 2026-07-01
Gradio HIGH 7.5
CVE-2026-49119

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers…

Fix: 6.16.0+
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-20191

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  …

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice HIGH 8.2
CVE-2026-53906

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.3
CVE-2026-56233

Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to b…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-50003

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, us…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 8.2
CVE-2026-52868

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment,…

Mitigation only
Fix from $1,950 2026-06-30