Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 6.5
CVE-2026-47118

Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying cra…

Patch available
Fix from $1,600 2026-05-27
Unclassified HIGH 7.5
CVE-2026-48544

Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/libr…

Patch available
Fix from $1,950 2026-05-27
Aspera High Speed Transfer Endpoint MEDIUM 6.5
CVE-2026-9035

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $1,600 2026-05-27
Langflow CRITICAL 9.8
CVE-2026-7524

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

Fix: after 1.9.1
Fix from $2,300 2026-05-27
Infosphere Optim Test Data Fabrication HIGH 7.5
CVE-2026-3366

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-42756

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Imag…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-42757

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-igni…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified HIGH 8.6
CVE-2026-42737

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo…

Mitigation only
Fix from $1,950 2026-05-27
Bosh MEDIUM 5.8
CVE-2026-41009

When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 33…

Fix: 282.1.12+
Fix from $1,600 2026-05-27
Sharpcompress MEDIUM 6.5
CVE-2026-44788

SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in…

Fix: after 0.47.4
Fix from $1,600 2026-05-26
Unclassified HIGH 8.2
CVE-2026-48126

Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turn…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified HIGH 8.7
CVE-2026-43982

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the ca…

Mitigation only
Fix from $1,950 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-40383

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! HIGH 7.5
CVE-2026-40384

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Fix: 5.4.6 / 6.1.1+
Fix from $1,950 2026-05-26
Unclassified HIGH 7.3
CVE-2026-9550

A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is so…

Mitigation only
Fix from $1,950 2026-05-26
\ CRITICAL 9.1
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() …

Fix: 3.08+
Fix from $2,300 2026-05-26
Unclassified MEDIUM 6.3
CVE-2026-9473

A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateIma…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9472

A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_do…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9468

A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the functi…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified HIGH 7.5
CVE-2018-25374

Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary fi…

No fix yet
Fix from $1,950 2026-05-25
Unclassified HIGH 7.5
CVE-2018-25365

PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative pat…

No fix yet
Fix from $1,950 2026-05-25
Unclassified HIGH 8.3
CVE-2026-7766

Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file pat…

Mitigation only
Fix from $1,950 2026-05-25
Spring Ai MEDIUM 6.5
CVE-2026-41863

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could all…

Fix: 1.1.7+
Fix from $1,600 2026-05-25
Unclassified HIGH 8.5
CVE-2026-9489

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified MEDIUM 6.5
CVE-2026-9351

A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the f…

Mitigation only
Fix from $1,600 2026-05-24
Unclassified MEDIUM 6.5
CVE-2026-36227

Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the…

Mitigation only
Fix from $1,600 2026-05-22
Unclassified HIGH 7.5
CVE-2025-45145

Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system…

Mitigation only
Fix from $1,950 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server HIGH 7.7
CVE-2026-34911

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access file…

Fix: 5.0.8 / 5.1.12+
Fix from $1,950 2026-05-22
Apex One CRITICAL 9.8
CVE-2025-71210

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $2,300 2026-05-21