Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Grafana Operator HIGH 8.8
CVE-2026-11769

We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation…

Fix: 5.24.0+
Fix from $1,950 2026-06-13
Unclassified MEDIUM 6.5
CVE-2026-11442

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive infor…

Mitigation only
Fix from $1,600 2026-06-13
Openclaw MEDIUM 6.5
CVE-2026-53825

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators …

Fix: 2026.4.7+
Fix from $1,600 2026-06-12
Unclassified CRITICAL 9.1
CVE-2026-53519

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the da…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-54394

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using or…

Patch available
Fix from $1,600 2026-06-12
Discourse MEDIUM 6.8
CVE-2026-45775

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l…

Fix: 2026.1.0 / 2026.1.4+
Fix from $1,600 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-43872

Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Ver…

Mitigation only
Fix from $1,600 2026-06-12
MariaDB HIGH 7.8
CVE-2026-44171

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11…

Fix: 10.6.26 / 10.11.17+
Fix from $1,950 2026-06-12
Mattermost Server HIGH 7.6
CVE-2026-6961

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received …

Fix: 10.11.17 / 11.5.5+
Fix from $1,950 2026-06-12
Kedro HIGH 7.1
CVE-2026-3840

A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()…

No fix yet
Fix from $1,950 2026-06-12
Unclassified HIGH 8.1
CVE-2026-11846

The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated rem…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified HIGH 8.6
CVE-2026-47368

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data fr…

Mitigation only
Fix from $1,950 2026-06-12
Idira Privileged Session Manager HIGH 8.8
CVE-2026-45171

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6…

Fix: 14.0.5 / 14.2.5+
Fix from $1,950 2026-06-11
macOS MEDIUM 5.5
CVE-2025-24268

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may…

Fix: 15.4+
Fix from $1,600 2026-06-11
Tmp HIGH 8.2
CVE-2026-49982

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that conta…

No fix yet
Fix from $1,950 2026-06-11
Tmp HIGH 8.2
CVE-2026-44705

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows es…

Fix: 0.2.6+
Fix from $1,950 2026-06-11
Unclassified HIGH 8.1
CVE-2026-53777

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writabl…

Patch available
Fix from $1,950 2026-06-11
Keras HIGH 8.1
CVE-2026-11816

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py…

Fix: 3.14.0+
Fix from $1,950 2026-06-11
Unclassified HIGH 8.3
CVE-2026-8464

Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitr…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 7.1
CVE-2026-40987

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) w…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 7.5
CVE-2026-52726

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcel…

Mitigation only
Fix from $1,950 2026-06-10
Imagemagick MEDIUM 5.5
CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect…

Fix: 6.9.13-48 / 7.1.2-24+
Fix from $1,600 2026-06-10
Unclassified CRITICAL 9.6
CVE-2026-46703

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted …

Mitigation only
Fix from $2,300 2026-06-10
Unclassified HIGH 8.8
CVE-2026-42305

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary fil…

Patch available
Fix from $1,950 2026-06-10
Cortex Xsoar HIGH 7.5
CVE-2026-0270

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent…

Fix: 8.13.0.11+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.7
CVE-2026-50567

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t…

Patch available
Fix from $1,950 2026-06-10
Unclassified HIGH 8.1
CVE-2026-45569

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validat…

Patch available
Fix from $1,950 2026-06-10
Unclassified HIGH 8.1
CVE-2026-45565

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxy…

Mitigation only
Fix from $1,950 2026-06-10
Assisted Migration Agent CRITICAL 9.6
CVE-2026-53476

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal…

Fix: 2026-06-07+
Fix from $2,300 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45556

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>…

Mitigation only
Fix from $2,300 2026-06-10