Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.4
CVE-2026-29509

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python …

Mitigation only
Fix from $1,600 2026-06-26
Extract Zip HIGH 8.1
CVE-2026-56876

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative…

Fix: after 2.0.1
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.5
CVE-2026-54557

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.5
CVE-2026-55677

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.1
CVE-2026-57321

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

No fix yet
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.8
CVE-2026-56066

Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-13426

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API rou…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.1
CVE-2025-55017

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.1
CVE-2025-64152

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57872

An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil…

Mitigation only
Fix from $1,950 2026-06-26
Cacti MEDIUM 6.5
CVE-2026-40084

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report fo…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Unclassified CRITICAL 9.1
CVE-2026-56445

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizatio…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified HIGH 8.2
CVE-2026-55667

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $1,950 2026-06-25
Seaweedfs CRITICAL 10.0
CVE-2026-54917

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceber…

Fix: 4.30+
Fix from $2,300 2026-06-25
Unclassified MEDIUM 6.8
CVE-2026-54093

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 7.5
CVE-2026-54094

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.8
CVE-2026-54250

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability …

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 7.8
CVE-2026-53925

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets …

Mitigation only
Fix from $1,950 2026-06-25
Cursor CRITICAL 9.8
CVE-2026-50548

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra…

Fix: 3.0+
Fix from $2,300 2026-06-25
Pnpm HIGH 7.1
CVE-2026-55700

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version…

Fix: 11.5.3+
Fix from $1,950 2026-06-25
Pnpm MEDIUM 6.5
CVE-2026-55699

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malic…

Fix: 10.34.2 / 11.5.3+
Fix from $1,600 2026-06-25
Pnpm HIGH 7.3
CVE-2026-50015

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file p…

Fix: 10.34.0 / 11.4.0+
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-55439

Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated ad…

Mitigation only
Fix from $1,600 2026-06-25
Trivy HIGH 7.5
CVE-2026-55092

Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the ar…

Fix: 0.71.1+
Fix from $1,950 2026-06-25
Unclassified HIGH 8.1
CVE-2026-45233

HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by sup…

Mitigation only
Fix from $1,950 2026-06-25
K2 MEDIUM 6.5
CVE-2026-48944

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::co…

Fix: after 2.26
Fix from $1,600 2026-06-25
Unclassified HIGH 7.7
CVE-2026-56054

Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-56122

Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sendi…

Mitigation only
Fix from $1,950 2026-06-25
Wyse Management Suite HIGH 7.2
CVE-2026-49506

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') …

Fix: 5.5+
Fix from $1,950 2026-06-25
Sed MEDIUM 6.5
CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express…

Mitigation only
Fix from $1,600 2026-06-25