Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.8
CVE-2026-40611

Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrar…

Mitigation only
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.4
CVE-2026-40576

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions u…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.8
CVE-2026-40050

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne…

Mitigation only
Fix from $2,300 2026-04-21
Apktool HIGH 7.1
CVE-2026-39973

Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decode…

Fix: 3.0.2+
Fix from $1,950 2026-04-21
Nbconvert MEDIUM 6.5
CVE-2026-39378

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when …

Fix: 7.17.1+
Fix from $1,600 2026-04-21
Claude Code CRITICAL 10.0
CVE-2026-39861

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks poin…

Fix: 2.1.64+
Fix from $2,300 2026-04-21
Nbconvert MEDIUM 6.5
CVE-2026-39377

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arb…

Fix: 7.17.1+
Fix from $1,600 2026-04-21
Openclaude HIGH 8.4
CVE-2026-35570

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `b…

Fix: 0.5.1+
Fix from $1,950 2026-04-21
Unclassified HIGH 8.1
CVE-2026-5478

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to …

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 8.1
CVE-2026-6248

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding …

Mitigation only
Fix from $1,950 2026-04-20
Junrar HIGH 7.5
CVE-2026-41245

Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attack…

Fix: 7.5.10+
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6620

A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the com…

Mitigation only
Fix from $1,600 2026-04-20
Threatsonar Anti Ransomware HIGH 8.1
CVE-2026-5966

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can expl…

Fix: 4.0.0+
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6615

A weakness has been identified in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function Upload of the file superagi/contro…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6568

A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controlle…

Mitigation only
Fix from $1,950 2026-04-19
Gdown HIGH 7.8
CVE-2026-40491

gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functi…

Fix: 5.2.2+
Fix from $1,950 2026-04-18
Unclassified CRITICAL 9.1
CVE-2026-40258

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerabil…

Patch available
Fix from $2,300 2026-04-17
Firebird CRITICAL 9.9
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con…

Fix: 3.0.14 / 4.0.7+
Fix from $2,300 2026-04-17
Unclassified HIGH 7.5
CVE-2026-5710

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in vers…

Mitigation only
Fix from $1,950 2026-04-17
Deerflow CRITICAL 9.1
CVE-2026-40518

ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation whe…

Patch available
Fix from $2,300 2026-04-17
Unclassified HIGH 8.8
CVE-2026-3464

The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_att…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified MEDIUM 5.4
CVE-2026-6496

A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POS…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified HIGH 7.5
CVE-2026-4659

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up…

Mitigation only
Fix from $1,950 2026-04-17
Debian Linux HIGH 7.8
CVE-2026-41082

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Fix: 2.5.1+
Fix from $1,950 2026-04-16
Fastify Static MEDIUM 5.3
CVE-2026-6410

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function …

Fix: 9.1.1+
Fix from $1,600 2026-04-16
Unclassified HIGH 8.8
CVE-2025-14868

The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all vers…

Mitigation only
Fix from $1,950 2026-04-16
Openharness MEDIUM 6.5
CVE-2026-40503

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files…

Fix: 2026-04-13+
Fix from $1,600 2026-04-16
Loki MEDIUM 5.3
CVE-2026-21726

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can …

Fix: 3.6.4+
Fix from $1,600 2026-04-15
Weblate MEDIUM 5.0
CVE-2026-40256

Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolu…

Fix: 5.17+
Fix from $1,600 2026-04-15
Weblate MEDIUM 6.8
CVE-2026-33220

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe…

Fix: 5.17+
Fix from $1,600 2026-04-15