Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Agixt HIGH 8.8
CVE-2026-39981

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that…

Fix: 1.9.2+
Fix from $1,950 2026-04-09
Ch22 Firmware CRITICAL 9.8
CVE-2026-5962

A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The ma…

Mitigation only
Fix from $2,300 2026-04-09
Helm HIGH 8.6
CVE-2026-35204

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm…

Fix: 4.1.4+
Fix from $1,950 2026-04-09
Unclassified HIGH 7.5
CVE-2026-4660

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously craf…

Mitigation only
Fix from $1,950 2026-04-09
I12 Firmware CRITICAL 9.8
CVE-2026-5849

A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a ma…

Mitigation only
Fix from $2,300 2026-04-09
I3 Firmware CRITICAL 9.8
CVE-2026-5841

A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. E…

Mitigation only
Fix from $2,300 2026-04-09
The Sleuth Kit HIGH 7.1
CVE-2026-40024

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations ou…

Fix: 4.15.0+
Fix from $1,950 2026-04-08
Unclassified HIGH 7.3
CVE-2026-40027

ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses a…

Patch available
Fix from $1,950 2026-04-08
Unclassified HIGH 8.1
CVE-2026-5436

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient …

Patch available
Fix from $1,950 2026-04-08
Nicegui HIGH 7.5
CVE-2026-39844

NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can …

Fix: 3.10.0+
Fix from $1,950 2026-04-08
Liquidjs HIGH 7.5
CVE-2026-39859

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining…

Fix: 10.25.3+
Fix from $1,950 2026-04-08
Logstash CRITICAL 9.8
CVE-2026-33466

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code executi…

Fix: 8.19.14 / 9.2.8+
Fix from $2,300 2026-04-08
Node Server MEDIUM 5.3
CVE-2026-39406

@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected sta…

Fix: after 1.19.12
Fix from $1,600 2026-04-08
Hono MEDIUM 5.3
CVE-2026-39407

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic …

Fix: after 4.12.11
Fix from $1,600 2026-04-08
Hono HIGH 7.5
CVE-2026-39408

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows file…

Fix: after 4.12.11
Fix from $1,950 2026-04-08
Unclassified HIGH 8.8
CVE-2026-3243

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_cro…

Mitigation only
Fix from $1,950 2026-04-08
Emmett HIGH 7.5
CVE-2026-39847

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal asset…

Fix: 2.8.1+
Fix from $1,950 2026-04-07
Flatpak HIGH 7.5
CVE-2026-34079

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without pro…

Fix: 1.16.4+
Fix from $1,950 2026-04-07
Librechat MEDIUM 6.3
CVE-2026-34371

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when pers…

Fix: 0.8.4+
Fix from $1,600 2026-04-07
Avideo HIGH 7.6
CVE-2026-39369

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploade…

Fix: after 26.0
Fix from $1,950 2026-04-07
Vite MEDIUM 5.3
CVE-2026-39365

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for opt…

Fix: after 8.0.4
Fix from $1,600 2026-04-07
Churchcrm CRITICAL 9.1
CVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allo…

Fix: 6.5.3+
Fix from $2,300 2026-04-07
Praisonai CRITICAL 10.0
CVE-2026-39305

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an att…

Fix: after 4.5.112
Fix from $2,300 2026-04-07
Praisonai HIGH 7.3
CVE-2026-39306

PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-controlled .praison tar archives w…

Fix: after 4.5.112
Fix from $1,950 2026-04-07
Praisonai HIGH 8.1
CVE-2026-39307

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File …

Fix: after 4.5.112
Fix from $1,950 2026-04-07
Praisonai HIGH 7.1
CVE-2026-39308

PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesyste…

Fix: after 4.5.112
Fix from $1,950 2026-04-07
Praisonai HIGH 7.5
CVE-2026-35615

PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collapses .. sequences, then checks…

Fix: 1.5.113+
Fix from $1,950 2026-04-07
Pyload Ng MEDIUM 6.5
CVE-2026-35592

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/ex…

Fix: after 0.5.0b3.dev96
Fix from $1,600 2026-04-07
Filebrowser HIGH 7.5
CVE-2026-35605

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Fix: 2.63.1+
Fix from $1,950 2026-04-07
Emissary MEDIUM 5.3
CVE-2026-35583

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration/{name}) validated configurat…

Fix: after 8.38.0
Fix from $1,600 2026-04-07