Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.3
CVE-2026-19758

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19757

A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the co…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19756

A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the compo…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73658

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73659

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.5
CVE-2026-17473

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a res…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.9
CVE-2026-45774

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profil…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-48099

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent…

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.8
CVE-2026-16908

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.2
CVE-2026-13048

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.6
CVE-2026-73509

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-70460

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.7
CVE-2026-65582

Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-61980

Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.4
CVE-2026-28189

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73620

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe opt…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.7
CVE-2026-73498

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment pa…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-64826

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized di…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-66898

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing …

No fix yet
Fix from $5,750 2026-08-12
I Access Client Solutions HIGH 8.8
CVE-2026-13105

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-13622

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.5
CVE-2026-16033

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image me…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.0
CVE-2026-73407

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials …

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 7.6
CVE-2026-73327

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a craft…

No fix yet
Fix from $4,900 2026-08-12
I MEDIUM 6.5
CVE-2026-17266

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to …

Fix: after 7.6
Fix from $4,000 2026-08-12
I HIGH 7.1
CVE-2026-17094

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal…

Fix unknown
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-66384

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within …

No fix yet
Fix from $4,000 2026-08-12