Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.3
CVE-2026-7214

A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/fi…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7205

A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the …

Mitigation only
Fix from $1,950 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41370

OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbou…

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41363

OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses…

Fix: 2026.3.28+
Fix from $1,600 2026-04-28
Unclassified MEDIUM 5.3
CVE-2026-7179

A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_null_terminated_string of the fi…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7159

A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Perf…

Mitigation only
Fix from $1,950 2026-04-27
Python HIGH 7.5
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted o…

Fix: after 3.14.4
Fix from $1,950 2026-04-27
Unclassified HIGH 7.3
CVE-2026-7149

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepar…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 8.8
CVE-2026-41463

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated att…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified MEDIUM 6.5
CVE-2026-41465

ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter …

Mitigation only
Fix from $1,600 2026-04-27
Unclassified HIGH 7.5
CVE-2026-30351

A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files via sending …

Mitigation only
Fix from $1,950 2026-04-27
Unclassified MEDIUM 5.3
CVE-2026-7132

A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.0
CVE-2026-7085

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/abo…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 5.3
CVE-2026-7059

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of…

Mitigation only
Fix from $1,600 2026-04-26
I9 Firmware CRITICAL 9.8
CVE-2026-7036

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP…

Mitigation only
Fix from $2,300 2026-04-26
Unclassified MEDIUM 5.4
CVE-2026-7024

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the fil…

Mitigation only
Fix from $1,600 2026-04-26
Tough MEDIUM 6.5
CVE-2026-6968

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file…

Fix: 0.15.0 / 0.22.0+
Fix from $1,600 2026-04-24
Opentelemetry Ebpf Instrumentation HIGH 8.4
CVE-2026-41433

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java …

Fix: 0.8.0+
Fix from $1,950 2026-04-24
Unclassified HIGH 7.1
CVE-2026-41894

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePat…

Patch available
Fix from $1,950 2026-04-24
Unclassified HIGH 7.6
CVE-2026-41419

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board…

Mitigation only
Fix from $1,950 2026-04-24
Unclassified HIGH 8.7
CVE-2026-41140

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs w…

Mitigation only
Fix from $1,950 2026-04-24
Roxy Wi CRITICAL 9.8
CVE-2026-33076

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
Roxy Wi HIGH 7.5
CVE-2026-33077

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the hapro…

Fix: 8.2.6.4+
Fix from $1,950 2026-04-24
Melange MEDIUM 6.1
CVE-2026-29050

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can i…

Fix: 0.43.4+
Fix from $1,600 2026-04-24
Radare2 HIGH 7.1
CVE-2026-6940

radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary direct…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Radare2 HIGH 7.8
CVE-2026-6941

radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Mako HIGH 7.5
CVE-2026-41205

Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with /…

Fix: 1.3.11+
Fix from $1,950 2026-04-23
Unclassified HIGH 7.5
CVE-2026-6903

The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated…

Mitigation only
Fix from $1,950 2026-04-23
Vite\+ CRITICAL 10.0
CVE-2026-41211

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` …

Fix: 0.1.17+
Fix from $2,300 2026-04-23
Unclassified HIGH 7.5
CVE-2026-41180

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates th…

Patch available
Fix from $1,950 2026-04-23