Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Apex One CRITICAL 9.8
CVE-2025-71211

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $2,300 2026-05-21
Mattermost Server CRITICAL 9.9
CVE-2026-4858

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which …

Fix: 10.11.15 / 11.4.5+
Fix from $2,300 2026-05-21
Unclassified HIGH 7.6
CVE-2026-44068

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to…

Mitigation only
Fix from $1,950 2026-05-21
Unclassified CRITICAL 9.4
CVE-2026-9129

A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.4
CVE-2026-9102

A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified HIGH 8.7
CVE-2026-39352

Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Pat…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified CRITICAL 9.4
CVE-2026-39405

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with cour…

Mitigation only
Fix from $2,300 2026-05-20
Triton Inference Server HIGH 7.5
CVE-2026-24208

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerabil…

Fix: 26.03+
Fix from $1,950 2026-05-20
Triton Inference Server HIGH 7.5
CVE-2026-24209

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerabil…

Fix: 26.03+
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.8
CVE-2026-35593

Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 an…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-36829

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified HIGH 7.3
CVE-2025-70950

An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.

Mitigation only
Fix from $1,950 2026-05-19
Unclassified MEDIUM 5.9
CVE-2026-46724

The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents …

Mitigation only
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-29220

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befor…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Unclassified CRITICAL 9.1
CVE-2026-45230

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allow…

Patch available
Fix from $2,300 2026-05-18
Mailinspector HIGH 7.5
CVE-2026-29963

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text …

Mitigation only
Fix from $1,950 2026-05-18
Private Cloud Compute MEDIUM 6.5
CVE-2026-20685

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation.…

Fix: 5e290.3+
Fix from $1,600 2026-05-18
Unclassified HIGH 7.5
CVE-2026-6381

The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to per…

Mitigation only
Fix from $1,950 2026-05-18
Kilo Code MEDIUM 6.5
CVE-2026-8765

A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/ki…

Fix: after 7.0.47
Fix from $1,600 2026-05-17
Hive CRITICAL 9.1
CVE-2026-8757

A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.…

Fix: after 0.11.0
Fix from $2,300 2026-05-17
Unclassified MEDIUM 6.3
CVE-2026-8754

A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of …

Patch available
Fix from $1,600 2026-05-17
Unclassified HIGH 7.3
CVE-2026-8755

A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of…

Mitigation only
Fix from $1,950 2026-05-17
Unclassified HIGH 7.3
CVE-2026-8756

A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_…

Mitigation only
Fix from $1,950 2026-05-17
Unclassified HIGH 7.5
CVE-2018-25326

Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting dir…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 7.5
CVE-2018-25325

Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unesca…

No fix yet
Fix from $1,950 2026-05-17
Unclassified HIGH 7.5
CVE-2021-47977

WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attac…

No fix yet
Fix from $1,950 2026-05-16
Unclassified HIGH 8.8
CVE-2021-47979

WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by ma…

No fix yet
Fix from $1,950 2026-05-16
Home Assistant Community Store HIGH 7.5
CVE-2021-47942

Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive…

Fix: 1.10.0+
Fix from $1,950 2026-05-16
Open Webui HIGH 8.1
CVE-2026-44565

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the…

Fix: 0.6.10+
Fix from $1,950 2026-05-15