Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.6
CVE-2026-41690

18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allo…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 8.2
CVE-2026-41693

i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.5
CVE-2026-41885

i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, …

Mitigation only
Fix from $1,600 2026-05-08
Praisonai HIGH 7.5
CVE-2026-44340

PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack…

Fix: 4.6.37+
Fix from $1,950 2026-05-08
Praisonai CRITICAL 9.6
CVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou…

Fix: 4.6.34+
Fix from $2,300 2026-05-08
Dapr HIGH 8.1
CVE-2026-41491

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-…

Fix: 1.15.14 / 1.16.14+
Fix from $1,950 2026-05-08
Yard HIGH 7.5
CVE-2026-41493

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve doc…

Fix: 0.9.42+
Fix from $1,950 2026-05-08
Nitrosense HIGH 7.8
CVE-2026-8069

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use…

Fix: 3.00.3198 / 3.01.3056+
Fix from $1,950 2026-05-08
Electerm HIGH 8.4
CVE-2026-43940

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/…

Fix: 3.7.16+
Fix from $1,950 2026-05-08
Zrok HIGH 8.7
CVE-2026-42275

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restri…

Fix: 2.0.2+
Fix from $1,950 2026-05-08
Unclassified MEDIUM 6.3
CVE-2026-8116

A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of the file src/controllers/dxt…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 5.3
CVE-2026-8115

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts …

Mitigation only
Fix from $1,600 2026-05-07
Miniclaw MEDIUM 6.5
CVE-2026-8113

A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vulnerability is the function isP…

Fix: 2026-03-27+
Fix from $1,600 2026-05-07
I18next Http Backend CRITICAL 9.1
CVE-2026-41691

Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag…

Fix: 3.0.5+
Fix from $2,300 2026-05-07
Gitpython HIGH 7.1
CVE-2026-44243

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can …

Fix: 3.1.48+
Fix from $1,950 2026-05-07
Wish CRITICAL 9.6
CVE-2026-41589

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wis…

No fix yet
Fix from $2,300 2026-05-07
Unclassified HIGH 8.1
CVE-2026-7252

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary f…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 6.5
CVE-2026-41655

Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template …

Mitigation only
Fix from $1,600 2026-05-07
Unclassified CRITICAL 9.4
CVE-2026-41202

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.4
CVE-2026-41203

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Mitigation only
Fix from $2,300 2026-05-07
Spring Cloud Config CRITICAL 9.1
CVE-2026-40982

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or …

Fix: 3.1.14 / 4.1.10+
Fix from $2,300 2026-05-07
Openmrs HIGH 8.8
CVE-2026-40076

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module …

Fix: after 2.8.5
Fix from $1,950 2026-05-06
Nanoclaw HIGH 8.8
CVE-2026-7875

NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that …

Fix: after 1.2.0
Fix from $1,950 2026-05-06
Wicket MEDIUM 6.5
CVE-2026-43975

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file p…

Fix: 10.9.0+
Fix from $1,600 2026-05-06
Cloud Infrastructure Cli MEDIUM 6.1
CVE-2026-35254

Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulne…

Mitigation only
Fix from $1,600 2026-05-06
Openmrs HIGH 7.5
CVE-2026-40075

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openm…

Fix: after 2.8.5
Fix from $1,950 2026-05-05
Jupyter Server HIGH 8.8
CVE-2026-35397

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an …

Fix: 2.18.0+
Fix from $1,950 2026-05-05
Unclassified CRITICAL 10.0
CVE-2026-7411

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticat…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified MEDIUM 6.5
CVE-2026-6262

The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() fu…

Mitigation only
Fix from $1,600 2026-05-05
Thrift HIGH 7.3
CVE-2026-43870

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…

Fix: 0.23.0+
Fix from $1,950 2026-05-05