Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.1
CVE-2026-73291

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.3
CVE-2026-67286

Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attac…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-66381

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.2
CVE-2026-67285

Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can p…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.1
CVE-2026-19594

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation thro…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-63134

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73244

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/sr…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.8
CVE-2026-73234

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp co…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-73034

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 5.0
CVE-2026-71475

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.1
CVE-2026-19091

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due t…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-73225

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-73227

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server t…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-73223

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72713

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitra…

No fix yet
Fix from $4,900 2026-08-11
Lightroom HIGH 8.6
CVE-2026-48441

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a…

Fix: 15.5+
Fix from $4,900 2026-08-11
Teams CRITICAL 9.8
CVE-2026-65768

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec…

Fix: 1.0.0.2026133602+
Fix from $5,750 2026-08-11
C2pa HIGH 7.1
CVE-2026-48442

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could res…

Fix: 0.12.1 / 0.27.6+
Fix from $4,900 2026-08-11
C2pa MEDIUM 5.5
CVE-2026-48446

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lea…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-32677

Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivil…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.5
CVE-2026-73079

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-18640

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.2
CVE-2026-72783

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContain…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72770

n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72602

A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listin…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72604

A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server v…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.0
CVE-2026-33922

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an i…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66777

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.6
CVE-2026-44763

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using s…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-73030

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize …

No fix yet
Fix from $4,900 2026-08-10