Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Open Webui CRITICAL 9.8
CVE-2026-44566

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp,…

Fix: 0.1.124+
Fix from $2,300 2026-05-15
Unclassified MEDIUM 5.5
CVE-2026-46383

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archiv…

No fix yet
Fix from $1,600 2026-05-15
Unclassified HIGH 7.1
CVE-2026-44641

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by …

Mitigation only
Fix from $1,950 2026-05-15
Unclassified CRITICAL 9.2
CVE-2026-7182

Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the ht…

Mitigation only
Fix from $2,300 2026-05-15
Pdf Export Module HIGH 7.5
CVE-2026-41552

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated …

Fix: 0.7.6+
Fix from $1,950 2026-05-15
Unclassified HIGH 7.5
CVE-2026-6403

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path val…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 7.1
CVE-2026-44647

OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected boundary between repository-cont…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.6
CVE-2026-44522

Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload ass…

No fix yet
Fix from $1,950 2026-05-14
Strapi HIGH 7.5
CVE-2026-27886

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer…

Fix: 5.37.0+
Fix from $1,950 2026-05-14
Filebrowser Quantum CRITICAL 9.1
CVE-2026-44542

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined wi…

Fix: 1.3.1 / 1.3.9+
Fix from $2,300 2026-05-14
Unclassified MEDIUM 6.9
CVE-2026-42598

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when request…

Mitigation only
Fix from $1,600 2026-05-14
Gotenberg MEDIUM 5.3
CVE-2026-42593

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert…

Fix: 8.32.0+
Fix from $1,600 2026-05-14
Unclassified HIGH 8.4
CVE-2026-42881

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) wit…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified MEDIUM 6.5
CVE-2026-6670

The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the 'sub_dir' and 'media_items' p…

Mitigation only
Fix from $1,600 2026-05-14
Erpnext MEDIUM 5.7
CVE-2026-44440

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restric…

Fix: 15.101.1 / 16.10.0+
Fix from $1,600 2026-05-13
Angular Cli MEDIUM 6.1
CVE-2026-44437

The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a…

Fix: 19.2.25 / 20.3.25+
Fix from $1,600 2026-05-13
Nitro MEDIUM 5.3
CVE-2026-44373

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path trav…

Fix: 2.13.4 / 3.0.260429+
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.5
CVE-2026-22677

Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbi…

Patch available
Fix from $1,600 2026-05-13
Unclassified HIGH 8.1
CVE-2026-6282

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenti…

Mitigation only
Fix from $1,950 2026-05-13
Openplc V3 Firmware MEDIUM 6.5
CVE-2026-31156

A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp…

No fix yet
Fix from $1,600 2026-05-13
Big Iq Centralized Management HIGH 8.1
CVE-2026-20916

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified HIGH 7.5
CVE-2020-37219

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating t…

No fix yet
Fix from $1,950 2026-05-13
Unclassified HIGH 8.7
CVE-2026-44307

Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the dir…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 7.6
CVE-2026-45225

Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled f…

Patch available
Fix from $1,950 2026-05-12
Hugo HIGH 8.1
CVE-2026-44301

Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, Tailwin…

Fix: 0.161.0+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.9
CVE-2026-42196

django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal …

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 8.8
CVE-2026-7474EPSS 7%

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnera…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-44225

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every …

Mitigation only
Fix from $2,300 2026-05-12
Commerce HIGH 8.7
CVE-2026-34653

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Path…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Substance 3d Designer MEDIUM 6.3
CVE-2026-34664

Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') …

Fix: after 15.1.0
Fix from $1,600 2026-05-12