Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Weblate HIGH 7.7
CVE-2026-34242

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following …

Fix: 5.17+
Fix from $1,950 2026-04-15
Unclassified HIGH 7.5
CVE-2026-30996

An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbit…

Mitigation only
Fix from $1,950 2026-04-15
Identity Services Engine CRITICAL 9.9
CVE-2026-20180EPSS 6%

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…

Fix: 3.2.0+
Fix from $2,300 2026-04-15
Zarf HIGH 7.1
CVE-2026-40090

Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf pa…

Fix: 0.74.2+
Fix from $1,950 2026-04-15
Unclassified MEDIUM 6.5
CVE-2025-15470

The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in the akd_required_plugin_callbac…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified CRITICAL 9.6
CVE-2026-39399

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi…

Patch available
Fix from $2,300 2026-04-14
Jellyfin HIGH 8.8
CVE-2026-35031

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V…

Fix: 10.11.7+
Fix from $1,950 2026-04-14
Coldfusion HIGH 7.7
CVE-2026-34619EPSS 9%

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $1,950 2026-04-14
Coldfusion HIGH 8.6
CVE-2026-27305EPSS 29%

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $1,950 2026-04-14
Powerchute Serial Shutdown MEDIUM 6.1
CVE-2026-2399

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritte…

Fix: 1.5+
Fix from $1,600 2026-04-14
Fortisandbox MEDIUM 6.7
CVE-2026-25691

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSan…

Fix: 4.4.9 / 5.0.6+
Fix from $1,600 2026-04-14
Fortisoar MEDIUM 6.5
CVE-2026-22573

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, Forti…

Fix: after 7.6.3
Fix from $1,600 2026-04-14
Fortimanager Cloud MEDIUM 6.5
CVE-2025-68649

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiA…

Fix: 7.4.8 / 7.6.5+
Fix from $1,600 2026-04-14
Fortios MEDIUM 6.5
CVE-2025-61624

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, For…

Fix: 1.7.1 / 7.0.7+
Fix from $1,600 2026-04-14
Unclassified HIGH 7.2
CVE-2026-6227

The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST en…

Mitigation only
Fix from $1,950 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-22562

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on t…

Mitigation only
Fix from $2,300 2026-04-13
Gleam HIGH 7.8
CVE-2026-32146

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependen…

Fix: 1.15.4+
Fix from $1,950 2026-04-11
Openclaw MEDIUM 6.5
CVE-2026-3689

OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on …

Fix: 2026.2.21+
Fix from $1,600 2026-04-11
Quarkus Openapi Generator HIGH 7.5
CVE-2026-40180

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzi…

Fix: 2.15.0+
Fix from $1,950 2026-04-10
Saltcorn HIGH 8.2
CVE-2026-40163

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes…

Fix: 1.4.5 / 1.5.5+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 8.3
CVE-2026-31939

Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file fe…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Praisonai HIGH 8.8
CVE-2026-40157

PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() withou…

Fix: 4.5.128+
Fix from $1,950 2026-04-10
Rembg MEDIUM 5.3
CVE-2026-40086

Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote a…

Fix: 2.0.75+
Fix from $1,600 2026-04-10
Openclaw HIGH 7.7
CVE-2026-35668

OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other…

Fix: 2026.3.24+
Fix from $1,950 2026-04-10
Unclassified CRITICAL 9.8
CVE-2026-6057

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrar…

Patch available
Fix from $2,300 2026-04-10
I6 Firmware CRITICAL 9.8
CVE-2026-6024

A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP …

Mitigation only
Fix from $2,300 2026-04-10
Unclassified MEDIUM 5.3
CVE-2026-5998

A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of t…

Patch available
Fix from $1,600 2026-04-10
Unclassified HIGH 8.1
CVE-2026-4351

The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This i…

Mitigation only
Fix from $1,950 2026-04-10
Praisonaiagents MEDIUM 5.3
CVE-2026-40152

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspac…

Fix: 1.5.128+
Fix from $1,600 2026-04-09
Flatpak Builder MEDIUM 6.3
CVE-2026-39977

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user d…

Fix: 1.4.8+
Fix from $1,600 2026-04-09