Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Tough MEDIUM 6.5
CVE-2026-6968

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file…

Fix: 0.15.0 / 0.22.0+
Fix from $1,600 2026-04-24
Opentelemetry Ebpf Instrumentation HIGH 8.4
CVE-2026-41433

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java …

Fix: 0.8.0+
Fix from $1,950 2026-04-24
Unclassified HIGH 7.1
CVE-2026-41894

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePat…

Patch available
Fix from $1,950 2026-04-24
Unclassified HIGH 7.6
CVE-2026-41419

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board…

Mitigation only
Fix from $1,950 2026-04-24
Unclassified HIGH 8.7
CVE-2026-41140

Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs w…

Mitigation only
Fix from $1,950 2026-04-24
Roxy Wi CRITICAL 9.8
CVE-2026-33076

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
Roxy Wi HIGH 7.5
CVE-2026-33077

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the hapro…

Fix: 8.2.6.4+
Fix from $1,950 2026-04-24
Melange MEDIUM 6.1
CVE-2026-29050

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can i…

Fix: 0.43.4+
Fix from $1,600 2026-04-24
Radare2 HIGH 7.1
CVE-2026-6940

radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary direct…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Radare2 HIGH 7.8
CVE-2026-6941

radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Mako HIGH 7.5
CVE-2026-41205

Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with /…

Fix: 1.3.11+
Fix from $1,950 2026-04-23
Unclassified HIGH 7.5
CVE-2026-6903

The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated…

Mitigation only
Fix from $1,950 2026-04-23
Vite\+ CRITICAL 10.0
CVE-2026-41211

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` …

Fix: 0.1.17+
Fix from $2,300 2026-04-23
Unclassified HIGH 7.5
CVE-2026-41180

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates th…

Patch available
Fix from $1,950 2026-04-23
Ziostation2 HIGH 7.5
CVE-2026-40062

A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the ope…

Fix: after 2.9.8.7
Fix from $1,950 2026-04-23
Espocrm CRITICAL 9.1
CVE-2026-33656

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing …

Fix: 9.3.4+
Fix from $2,300 2026-04-22
Unclassified HIGH 7.1
CVE-2026-34414

Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinde…

Patch available
Fix from $1,950 2026-04-22
Coreutils MEDIUM 5.6
CVE-2026-35363

A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the …

No fix yet
Fix from $1,600 2026-04-22
Coreutils HIGH 7.3
CVE-2026-35338

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validat…

Fix: 0.6.0+
Fix from $1,950 2026-04-22
Ddev CRITICAL 9.1
CVE-2026-32885

DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction …

Fix: 1.25.2+
Fix from $2,300 2026-04-22
Instructlab HIGH 7.1
CVE-2026-6855

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…

Mitigation only
Fix from $1,950 2026-04-22
Unclassified MEDIUM 6.5
CVE-2026-4280

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_a…

Mitigation only
Fix from $1,600 2026-04-22
Avideo HIGH 8.1
CVE-2026-41058

WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not a…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-41062

WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVi…

Fix: after 29.0
Fix from $1,600 2026-04-21
Hermes Web Ui HIGH 8.1
CVE-2026-6832

Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete file…

Fix: 0.50.32+
Fix from $1,950 2026-04-21
Unclassified MEDIUM 6.3
CVE-2026-6829

nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an …

Patch available
Fix from $1,600 2026-04-21
Tekton Pipelines MEDIUM 5.4
CVE-2026-40923

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…

Fix: 1.11.1+
Fix from $1,600 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-40909

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by dire…

Fix: after 29.0
Fix from $1,600 2026-04-21
Goshs HIGH 8.8
CVE-2026-40876

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authe…

Fix: 2.0.0+
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.1
CVE-2026-41193

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives…

Patch available
Fix from $2,300 2026-04-21