Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Sed MEDIUM 6.5
CVE-2026-9154

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content t…

Mitigation only
Fix from $1,600 2026-06-25
Cacti MEDIUM 5.3
CVE-2026-39899

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter…

Fix: 1.2.31+
Fix from $1,600 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39938

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Unizon MEDIUM 6.5
CVE-2026-9774

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary f…

Fix: 2.7.264+
Fix from $1,600 2026-06-24
Unizon MEDIUM 6.5
CVE-2026-9775

ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files…

Fix: 2.7.264+
Fix from $1,600 2026-06-24
Unizon HIGH 7.5
CVE-2026-9776

ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to di…

Fix: 2.7.264+
Fix from $1,950 2026-06-24
Unizon HIGH 7.2
CVE-2026-9777

ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

Fix: 2.7.264+
Fix from $1,950 2026-06-24
Unizon HIGH 7.2
CVE-2026-9778

ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Fix: 2.7.264+
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-54066

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding"…

Mitigation only
Fix from $1,950 2026-06-24
Chrome Devtools Mcp MEDIUM 6.1
CVE-2026-53766

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContex…

Fix: 1.1.0+
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.0
CVE-2026-52811

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload tar…

Patch available
Fix from $2,300 2026-06-24
Unclassified HIGH 8.5
CVE-2026-52797

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-31978

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 ar…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.8
CVE-2026-49247

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization head…

Mitigation only
Fix from $1,950 2026-06-24
Docling HIGH 7.5
CVE-2026-44017

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the E…

Fix: 2.91.0+
Fix from $1,950 2026-06-24
Docling MEDIUM 5.5
CVE-2026-44022

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91…

Fix: 2.91.0+
Fix from $1,600 2026-06-24
Unclassified HIGH 7.7
CVE-2026-55488

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Version…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exw…

No fix yet
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-47385

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create permission can attach a SQLite …

Mitigation only
Fix from $1,600 2026-06-23
Traefik CRITICAL 10.0
CVE-2026-48020

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPre…

Fix: 2.11.48 / 3.6.19+
Fix from $2,300 2026-06-23
Caddy HIGH 7.5
CVE-2026-52844

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outsid…

Fix: 2.11.4+
Fix from $1,950 2026-06-23
Deno MEDIUM 5.5
CVE-2026-49406

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module re…

Fix: 2.7.12+
Fix from $1,600 2026-06-23
N8n HIGH 7.7
CVE-2026-49465

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify …

Fix: 1.123.48 / 2.21.8+
Fix from $1,950 2026-06-23
Langflow MEDIUM 6.5
CVE-2026-42867

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle…

Fix: 1.9.0+
Fix from $1,600 2026-06-23
Unclassified HIGH 7.8
CVE-2026-11940

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deepe…

Patch available
Fix from $1,950 2026-06-23
Crawl4ai HIGH 8.1
CVE-2026-56258

Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to wri…

Fix: 0.8.8+
Fix from $1,950 2026-06-23
Langchain MEDIUM 5.5
CVE-2026-55443

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths…

Fix: 1.3.9+
Fix from $1,600 2026-06-22
Nltk HIGH 7.5
CVE-2026-54293

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…

Fix: 3.10.0+
Fix from $1,950 2026-06-22
Unclassified HIGH 7.5
CVE-2026-53779

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the conf…

Patch available
Fix from $1,950 2026-06-22
Unclassified MEDIUM 5.9
CVE-2026-54286

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) …

Mitigation only
Fix from $1,600 2026-06-22