Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Vertex HIGH 8.6
CVE-2024-40646

Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc9…

Fix: 2024-07-17+
Fix from $1,950 2026-06-01
Mina Sshd HIGH 7.1
CVE-2026-48827

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operati…

Fix: 2.18.0+
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.4
CVE-2026-40547

SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.4
CVE-2026-10213

A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the comp…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.5
CVE-2018-25421

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file par…

No fix yet
Fix from $1,600 2026-05-30
Unclassified HIGH 7.5
CVE-2018-25408

The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to downlo…

No fix yet
Fix from $1,950 2026-05-30
Unclassified CRITICAL 9.1
CVE-2026-44650

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 7.7
CVE-2026-47179

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns t…

Patch available
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45661

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.3
CVE-2026-45668

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malic…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 7.5
CVE-2026-10108

xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated att…

Patch available
Fix from $1,950 2026-05-29
Emlog HIGH 7.2
CVE-2026-39276

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP co…

No fix yet
Fix from $1,950 2026-05-29
Unclassified MEDIUM 6.5
CVE-2018-25393

Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory travers…

No fix yet
Fix from $1,600 2026-05-29
Avideo MEDIUM 5.3
CVE-2026-46337

WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk…

Fix: after 29.0
Fix from $1,600 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-9559

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw …

Mitigation only
Fix from $2,300 2026-05-29
Portainer MEDIUM 5.5
CVE-2026-44885

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8+
Fix from $1,600 2026-05-28
Unclassified HIGH 8.1
CVE-2026-44973

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. In…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.5
CVE-2026-49128

Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 with…

Patch available
Fix from $1,950 2026-05-28
Deepcode HIGH 7.5
CVE-2026-32847

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthentica…

Fix: after 1.2.0
Fix from $1,950 2026-05-28
Kibana HIGH 7.3
CVE-2026-33462

A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could cr…

Fix: 8.19.16 / 9.3.5+
Fix from $1,950 2026-05-28
Unclassified HIGH 8.8
CVE-2026-4944

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files…

Mitigation only
Fix from $1,950 2026-05-28
Python Liquid HIGH 7.5
CVE-2026-45017

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not g…

Fix: 2.2.0+
Fix from $1,950 2026-05-28
Unclassified HIGH 8.7
CVE-2026-44593

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacy…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.5
CVE-2026-44594

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the…

Mitigation only
Fix from $1,950 2026-05-28
Multipass HIGH 8.4
CVE-2026-49238

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root pr…

Fix: 1.16.3+
Fix from $1,950 2026-05-28
Unclassified HIGH 8.5
CVE-2026-9789

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.1
CVE-2026-46402

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-contro…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-44635

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metachara…

Mitigation only
Fix from $1,950 2026-05-27
Streamlink MEDIUM 6.5
CVE-2026-44353

Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do…

Fix: 8.4.0+
Fix from $1,600 2026-05-27
Go Git MEDIUM 5.4
CVE-2026-45571

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could all…

Fix: 5.19.1+
Fix from $1,600 2026-05-27