Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Websphere Application Server HIGH 7.5
CVE-2026-11595

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integra…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-06-30
Unclassified HIGH 8.1
CVE-2026-58372

SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals …

Patch available
Fix from $1,950 2026-06-30
Unclassified HIGH 8.3
CVE-2026-58170

Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without…

Patch available
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-58173

Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by…

Patch available
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.1
CVE-2026-58166

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write…

Patch available
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 9.3
CVE-2026-48313

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion MEDIUM 6.5
CVE-2026-48314

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $1,600 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48282 KEVEPSS 99%

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $2,300 2026-06-30
Enterprise Linux HIGH 7.5
CVE-2026-58015

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con…

Fix: 2.88.1+
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-57079

Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorr…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-11367

The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the m…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 8.4
CVE-2026-58302

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlo…

Patch available
Fix from $1,950 2026-06-30
Nltk HIGH 7.5
CVE-2026-12243

NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `n…

No fix yet
Fix from $1,950 2026-06-30
Zephyr HIGH 7.5
CVE-2026-8023

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTE…

Fix: after 4.4.1
Fix from $1,950 2026-06-29
Safari MEDIUM 6.5
CVE-2026-43732

A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2,…

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Gigavue Os HIGH 7.5
CVE-2026-36848

Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

Fix: after 5.16.1
Fix from $1,950 2026-06-29
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11720

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL bui…

Fix: 1.3.0+
Fix from $2,300 2026-06-29
Snowflake Cli MEDIUM 6.3
CVE-2026-13748

Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted …

Fix: 3.19.0+
Fix from $1,600 2026-06-29
Unclassified CRITICAL 9.9
CVE-2026-57331

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

Mitigation only
Fix from $2,300 2026-06-29
Claude Code HIGH 8.8
CVE-2026-55607

Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and nav…

Fix: 2.1.163+
Fix from $1,950 2026-06-29
Unclassified HIGH 8.8
CVE-2026-40521

FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute…

Patch available
Fix from $1,950 2026-06-29
Unclassified HIGH 7.1
CVE-2026-57346

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This is…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13528

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.3
CVE-2026-13509

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp…

Patch available
Fix from $1,600 2026-06-28
Unclassified MEDIUM 5.3
CVE-2026-13503

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr…

Mitigation only
Fix from $1,600 2026-06-28
Dmp 5000 Firmware MEDIUM 5.3
CVE-2026-28701

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and en…

Fix: 8.117.0.0 / 9.43.0.0+
Fix from $1,600 2026-06-26
Kestra HIGH 7.7
CVE-2026-49984

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied…

Fix: 1.0.45 / 1.3.23+
Fix from $1,950 2026-06-26
Kestra HIGH 7.7
CVE-2026-45807

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from t…

Fix: 1.0.43 / 1.3.19+
Fix from $1,950 2026-06-26
Budibase CRITICAL 9.6
CVE-2026-54352

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a b…

Fix: 3.39.9+
Fix from $2,300 2026-06-26
Unclassified HIGH 8.6
CVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket …

Mitigation only
Fix from $1,950 2026-06-26