Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.5
CVE-2026-5192

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and i…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7811

A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element is the function is_safe_path o…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified MEDIUM 6.5
CVE-2026-5957

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traver…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7810

A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_n…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7788

A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the functio…

Mitigation only
Fix from $1,950 2026-05-05
Unclassified HIGH 7.3
CVE-2026-7784

A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.…

Mitigation only
Fix from $1,950 2026-05-05
Fast Uri HIGH 7.5
CVE-2026-6321

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encod…

Fix: 3.1.1+
Fix from $1,950 2026-05-04
Unclassified HIGH 8.1
CVE-2026-42075

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) co…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7738

A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-se…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7728

A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0. This vulnerability affects the function get_doc_content/read_doc/update_doc of the comp…

Patch available
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7715

A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. This affects the function arango_backup of the file src/tools.ts of the …

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.5
CVE-2026-7645

A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciou…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified HIGH 7.5
CVE-2026-6320

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7627

A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file…

Mitigation only
Fix from $1,600 2026-05-02
Unclassified MEDIUM 6.3
CVE-2026-7599

A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_to_html of the file mcp-server…

Mitigation only
Fix from $1,600 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7594

A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the componen…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified MEDIUM 5.3
CVE-2026-7589

A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_…

Mitigation only
Fix from $1,600 2026-05-01
Unclassified MEDIUM 5.3
CVE-2026-7588

A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_practices of the file server.py. T…

Mitigation only
Fix from $1,600 2026-05-01
Automotive Grade Linux CRITICAL 9.8
CVE-2026-37531

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the …

Fix: after 17.1.12
Fix from $2,300 2026-05-01
Unclassified HIGH 7.3
CVE-2026-7519

A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component En…

Mitigation only
Fix from $1,950 2026-05-01
Wireshark HIGH 7.8
CVE-2026-5656

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-05-01
Langflow Desktop MEDIUM 6.5
CVE-2026-3345

IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Langflow Desktop MEDIUM 6.5
CVE-2026-4502

IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Traefik HIGH 8.2
CVE-2026-40912

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass…

Fix: 2.11.43 / 3.6.14+
Fix from $1,950 2026-04-30
Unclassified HIGH 8.8
CVE-2026-36762

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions …

Mitigation only
Fix from $1,950 2026-04-30
Unclassified CRITICAL 9.6
CVE-2026-36760

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to ex…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified CRITICAL 10.0
CVE-2026-36767

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path vi…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified HIGH 7.5
CVE-2022-50992

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpo…

Mitigation only
Fix from $1,950 2026-04-30
Coloros Assistant CRITICAL 9.8
CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Mitigation only
Fix from $2,300 2026-04-30
Unclassified MEDIUM 6.3
CVE-2026-7445

A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src…

Mitigation only
Fix from $1,600 2026-04-30