Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Ghidra HIGH 7.8
CVE-2026-52752

Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Att…

Fix: 12.0.2+
Fix from $1,950 2026-06-10
Ghidra HIGH 7.8
CVE-2026-52755

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the inten…

Fix: 12.0.4+
Fix from $1,950 2026-06-10
Ghidra MEDIUM 6.5
CVE-2026-52756

Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied …

Fix: after 12.1.2
Fix from $1,600 2026-06-10
Qts MEDIUM 6.5
CVE-2026-24717

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator accoun…

Fix: 5.2.9.3492+
Fix from $1,600 2026-06-10
Pipecat HIGH 7.5
CVE-2026-44716

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1…

Fix: 1.2.0+
Fix from $1,950 2026-06-10
Unclassified HIGH 8.6
CVE-2026-46491

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module…

Patch available
Fix from $1,950 2026-06-10
C2pa MEDIUM 5.5
CVE-2026-34657

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direct…

Fix: after 0.80.1
Fix from $1,600 2026-06-09
Coldfusion HIGH 8.8
CVE-2026-47932

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-36726

An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete …

Mitigation only
Fix from $1,600 2026-06-09
Unclassified HIGH 8.8
CVE-2026-36723

An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory tra…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 7.7
CVE-2026-49957

Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-roo…

Patch available
Fix from $1,950 2026-06-09
Visual Studio Code HIGH 8.4
CVE-2026-45482

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attack…

Fix: 1.123.2+
Fix from $1,950 2026-06-09
Sharepoint Server HIGH 8.8
CVE-2026-45454

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execut…

Fix: 16.0.19725.20384+
Fix from $1,950 2026-06-09
Azure Kubernetes Service HIGH 8.8
CVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to…

Fix: 2026-02-13.5+
Fix from $1,950 2026-06-09
Unclassified HIGH 7.8
CVE-2026-22926

Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 7.5
CVE-2017-20248

Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating t…

No fix yet
Fix from $1,950 2026-06-09
Unclassified HIGH 7.5
CVE-2017-20250

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the a…

No fix yet
Fix from $1,950 2026-06-09
Unclassified HIGH 7.1
CVE-2026-49742

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media …

Patch available
Fix from $1,950 2026-06-09
Apache Airflow Providers Samba MEDIUM 6.5
CVE-2026-49818

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec…

Fix: 4.12.6+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.4
CVE-2026-41972

Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-06-09
Spring Framework MEDIUM 5.9
CVE-2026-41843

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.…

Fix: 5.3.49 / 6.1.28+
Fix from $1,600 2026-06-09
Unclassified HIGH 8.1
CVE-2026-46484

Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / author…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified MEDIUM 5.3
CVE-2026-46486

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise. Prior to versio…

Mitigation only
Fix from $1,600 2026-06-08
Unclassified CRITICAL 9.4
CVE-2026-41448

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full…

Mitigation only
Fix from $2,300 2026-06-08
Unclassified HIGH 8.8
CVE-2026-25559

OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arb…

Mitigation only
Fix from $1,950 2026-06-08
Routinator HIGH 7.5
CVE-2026-49233

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This …

Fix: 0.15.2+
Fix from $1,950 2026-06-08
Unclassified HIGH 8.7
CVE-2026-9506

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remo…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified MEDIUM 6.2
CVE-2022-50953

WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files b…

No fix yet
Fix from $1,600 2026-06-08
Unclassified MEDIUM 6.3
CVE-2026-11470

A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-syst…

Patch available
Fix from $1,600 2026-06-08
Unclassified MEDIUM 5.4
CVE-2026-11467

A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the fil…

Mitigation only
Fix from $1,600 2026-06-08