Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.5
CVE-2026-9290

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi…

Patch available
Fix from $1,950 2026-06-06
Unclassified HIGH 8.1
CVE-2026-11416

MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path i…

Patch available
Fix from $1,950 2026-06-05
Unclassified CRITICAL 10.0
CVE-2026-11429

Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified HIGH 8.3
CVE-2026-11431

A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated u…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified CRITICAL 9.4
CVE-2026-11423

A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in th…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified MEDIUM 6.5
CVE-2026-46397

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerabili…

Mitigation only
Fix from $1,600 2026-06-05
On Prem Enterprise Server CRITICAL 9.8
CVE-2026-11414

A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro…

Fix: 8.1.1+
Fix from $2,300 2026-06-05
On Prem Enterprise Server HIGH 8.8
CVE-2026-11419

A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled …

Fix: 8.1.1+
Fix from $1,950 2026-06-05
On Prem Enterprise Server CRITICAL 9.8
CVE-2026-11420

Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to…

Fix: 8.1.1+
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.1
CVE-2026-36500

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted reques…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified HIGH 7.5
CVE-2026-50234

Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directo…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified MEDIUM 6.4
CVE-2026-10732

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive contain…

Patch available
Fix from $1,600 2026-06-05
Unclassified MEDIUM 6.9
CVE-2026-7774

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive me…

Patch available
Fix from $1,600 2026-06-04
Unclassified MEDIUM 5.7
CVE-2026-40605

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache d…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified MEDIUM 6.5
CVE-2019-25740

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom …

No fix yet
Fix from $1,600 2026-06-04
Unclassified CRITICAL 9.8
CVE-2019-25727

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive f…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware HIGH 7.8
CVE-2026-50207

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellula…

Mitigation only
Fix from $1,950 2026-06-04
Universal Gateway Firmware HIGH 8.8
CVE-2026-35082

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied …

Fix: 6_00_07+
Fix from $1,950 2026-06-03
Unclassified MEDIUM 6.5
CVE-2026-49144

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated n…

Mitigation only
Fix from $1,600 2026-06-02
Fd8136 Firmware MEDIUM 6.5
CVE-2026-35718

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.6
CVE-2026-43965

Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content.…

Patch available
Fix from $1,600 2026-06-02
Android MEDIUM 6.2
CVE-2026-0055

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.5
CVE-2026-49136

Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI servic…

Patch available
Fix from $1,950 2026-06-01
Unclassified HIGH 8.8
CVE-2026-45727

CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint quer…

Mitigation only
Fix from $1,950 2026-06-01
Nextcloud Server MEDIUM 6.5
CVE-2026-45279

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, …

Fix: 28.0.14.15 / 29.0.17.12+
Fix from $1,600 2026-06-01
Unclassified HIGH 8.2
CVE-2026-43624

F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write …

Patch available
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10278

A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file…

Mitigation only
Fix from $1,600 2026-06-01
Pip MEDIUM 5.5
CVE-2026-8643

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation dire…

Fix: 26.1.2+
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.5
CVE-2026-42679

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Travers…

No fix yet
Fix from $1,600 2026-06-01
Unclassified CRITICAL 9.6
CVE-2026-48866

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal…

Mitigation only
Fix from $2,300 2026-06-01