Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Vite HIGH 7.5
CVE-2026-53571

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny ca…

Fix: 0.1.24 / 6.4.3+
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.1
CVE-2026-12479

A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model savi…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified HIGH 8.3
CVE-2026-56448

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticate…

Patch available
Fix from $1,950 2026-06-22
Loki Datasource HIGH 7.7
CVE-2026-42129

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive back…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12821

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/do…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.5
CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not vali…

Patch available
Fix from $1,600 2026-06-21
Unclassified HIGH 7.5
CVE-2026-11911

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile f…

Mitigation only
Fix from $1,950 2026-06-20
Unclassified HIGH 8.1
CVE-2026-9843

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…

Mitigation only
Fix from $1,950 2026-06-20
Unclassified MEDIUM 6.5
CVE-2026-48129

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes …

Mitigation only
Fix from $1,600 2026-06-19
Unclassified MEDIUM 5.3
CVE-2026-49342

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path b…

Patch available
Fix from $1,600 2026-06-19
Unclassified HIGH 7.1
CVE-2026-49339

gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a7d…

Patch available
Fix from $1,950 2026-06-19
Unclassified HIGH 8.1
CVE-2026-49340

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdateP…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified HIGH 7.6
CVE-2026-49290

Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-…

Patch available
Fix from $1,950 2026-06-19
Unclassified MEDIUM 5.3
CVE-2026-56138

AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2…

Patch available
Fix from $1,600 2026-06-19
Unclassified CRITICAL 9.1
CVE-2026-8713

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete…

Mitigation only
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.8
CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitr…

No fix yet
Fix from $2,300 2026-06-19
Unclassified HIGH 8.8
CVE-2026-56078

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Atta…

Mitigation only
Fix from $1,950 2026-06-18
Open Webui HIGH 7.7
CVE-2026-54017

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy …

Fix: 0.9.6+
Fix from $1,950 2026-06-18
Unclassified HIGH 8.7
CVE-2026-48716

nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path usi…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 8.6
CVE-2026-54223

UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s serv…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 7.1
CVE-2026-8811

SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to crea…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.3
CVE-2026-48768

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses uns…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified MEDIUM 6.5
CVE-2026-12568

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malic…

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 5.3
CVE-2026-12565

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavio…

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.3
CVE-2026-48820

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.5
CVE-2026-49133

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary fil…

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.8
CVE-2026-55201

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compro…

Patch available
Fix from $1,600 2026-06-17
Unclassified HIGH 7.5
CVE-2026-53872

picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by…

Mitigation only
Fix from $1,950 2026-06-17
Identity Services Engine CRITICAL 9.1
CVE-2026-20181

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating syst…

Fix: 3.3.0+
Fix from $2,300 2026-06-17
Unclassified HIGH 7.7
CVE-2026-54193

Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.

Mitigation only
Fix from $1,950 2026-06-17