Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Live Preview MEDIUM 5.5
CVE-2026-41612

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

Fix: 0.4.19+
Fix from $1,600 2026-05-12
Langflow CRITICAL 9.6
CVE-2026-42048

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle…

Fix: 1.9.0+
Fix from $2,300 2026-05-12
Unclassified HIGH 8.5
CVE-2026-43989

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 7.1
CVE-2026-6865

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitiv…

No fix yet
Fix from $1,950 2026-05-12
Wireshark Mcp MEDIUM 6.8
CVE-2026-43901

Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 an…

Fix: after 1.1.5
Fix from $1,600 2026-05-11
Unclassified HIGH 8.7
CVE-2026-43888

Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by pa…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 8.2
CVE-2026-42564

jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-ic…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.9
CVE-2026-42888

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.…

Mitigation only
Fix from $1,600 2026-05-11
macOS HIGH 7.8
CVE-2026-28915

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS So…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.4
CVE-2026-42882

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path inte…

Patch available
Fix from $2,300 2026-05-11
Mlflow HIGH 7.5
CVE-2026-2614

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthe…

Fix: 3.10.0+
Fix from $1,950 2026-05-11
Unclassified HIGH 7.1
CVE-2026-45224

Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolut…

Patch available
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.7
CVE-2026-42866

Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write_json, and (commented-but-shi…

Mitigation only
Fix from $1,600 2026-05-11
Pyload Ng MEDIUM 6.5
CVE-2026-42314

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient s…

Fix: 0.5.0b3.dev100+
Fix from $1,600 2026-05-11
Pyload Ng MEDIUM 6.5
CVE-2026-42315

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() AP…

Fix: 0.5.0b3.dev100+
Fix from $1,600 2026-05-11
Casdoor MEDIUM 5.9
CVE-2026-6815

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated…

Fix: after 2.328.0
Fix from $1,600 2026-05-11
Grav CRITICAL 9.1
CVE-2026-42608

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulatin…

Fix: 2.0.0+
Fix from $2,300 2026-05-11
Unclassified HIGH 7.5
CVE-2025-65418

docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.2
CVE-2026-41951

Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8274

A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of the file cramfsck.c of the comp…

Patch available
Fix from $1,600 2026-05-11
Unclassified MEDIUM 6.2
CVE-2022-50956

WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files …

No fix yet
Fix from $1,600 2026-05-10
Unclassified MEDIUM 5.3
CVE-2026-8215

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This vulnerability affects the function iasRequestFileEvent of…

Mitigation only
Fix from $1,600 2026-05-10
Azuracast HIGH 8.8
CVE-2026-42605

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js med…

Fix: 0.23.6+
Fix from $1,950 2026-05-09
Unclassified HIGH 7.5
CVE-2026-42574

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk coul…

Patch available
Fix from $1,950 2026-05-09
Unclassified HIGH 7.5
CVE-2026-42351

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concate…

Patch available
Fix from $1,950 2026-05-08
Unclassified MEDIUM 5.1
CVE-2026-42213

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th…

Patch available
Fix from $1,600 2026-05-08
Smartermail HIGH 8.8
CVE-2026-7807

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that all…

Fix: 100.0.9560+
Fix from $1,950 2026-05-08
Unclassified MEDIUM 5.3
CVE-2026-42028

novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenti…

Patch available
Fix from $1,600 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-38360EPSS 6%

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash…

Patch available
Fix from $2,300 2026-05-08
Unclassified HIGH 8.2
CVE-2026-42353

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18…

Mitigation only
Fix from $1,950 2026-05-08