Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 6.5
CVE-2026-35492

Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vulnerable to path traversal. Pa…

Patch available
Fix from $1,600 2026-04-07
Text Generation Web Ui MEDIUM 5.3
CVE-2026-35487

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerabilit…

Fix: 4.3+
Fix from $1,600 2026-04-07
Textgen MEDIUM 5.3
CVE-2026-35483

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerabilit…

Fix: 4.3+
Fix from $1,600 2026-04-07
Textgen MEDIUM 5.3
CVE-2026-35484

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerabilit…

Fix: 4.3+
Fix from $1,600 2026-04-07
Textgen HIGH 7.5
CVE-2026-35485

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerabilit…

Fix: 4.3+
Fix from $1,950 2026-04-07
Code Marketplace MEDIUM 6.5
CVE-2026-35454

The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketp…

Fix: after 2.4.1
Fix from $1,600 2026-04-06
Goshs CRITICAL 9.8
CVE-2026-35471

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixe…

Fix: 2.0.0+
Fix from $2,300 2026-04-06
Goshs CRITICAL 9.8
CVE-2026-35392

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is …

Fix: 2.0.0+
Fix from $2,300 2026-04-06
Goshs CRITICAL 9.8
CVE-2026-35393

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2…

Fix: 2.0.0+
Fix from $2,300 2026-04-06
Vim HIGH 7.1
CVE-2026-35177

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary f…

Fix: 9.2.0280+
Fix from $1,950 2026-04-06
Kedro HIGH 8.1
CVE-2026-35167

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem path…

Fix: 1.3.0+
Fix from $1,950 2026-04-06
Chyrp Lite HIGH 7.2
CVE-2026-35174

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows…

Fix: 2026.01+
Fix from $1,950 2026-04-06
Textgen HIGH 8.8
CVE-2026-35050

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in "py" fo…

Fix: 4.1.1+
Fix from $1,950 2026-04-06
Ferret HIGH 8.1
CVE-2026-34783

Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard l…

Fix: 2.0.0+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5638

A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5597

A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component Compu…

Mitigation only
Fix from $1,600 2026-04-05
Pegasus Cms CRITICAL 9.8
CVE-2019-25687

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitr…

Mitigation only
Fix from $2,300 2026-04-05
Unclassified HIGH 8.8
CVE-2019-25671

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell meta…

No fix yet
Fix from $1,950 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5595

A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_f…

Mitigation only
Fix from $1,600 2026-04-05
Fedml MEDIUM 5.4
CVE-2026-5535

A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT …

Fix: 0.8.9+
Fix from $1,600 2026-04-05
Unclassified HIGH 8.8
CVE-2026-3666

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing…

Mitigation only
Fix from $1,950 2026-04-04
Emlog HIGH 7.2
CVE-2026-34607

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (includ…

Fix: after 2.6.2
Fix from $1,950 2026-04-03
Cups MEDIUM 6.5
CVE-2026-34978

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier a…

Fix: after 2.4.16
Fix from $1,600 2026-04-03
Zulip MEDIUM 6.1
CVE-2026-26058

Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server …

Fix: after 11.5
Fix from $1,600 2026-04-03
Prompts.chat HIGH 8.1
CVE-2026-22661

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to…

Fix: 2026-03-25+
Fix from $1,950 2026-04-03
Stackfield CRITICAL 9.6
CVE-2026-28373

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when proce…

Fix: 1.10.2+
Fix from $2,300 2026-04-03
Budibase HIGH 8.7
CVE-2026-35214

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supp…

Fix: 3.33.4+
Fix from $1,950 2026-04-03
Biztalk360 HIGH 8.3
CVE-2025-59711

An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is…

Fix: 11.6.3963.2611+
Fix from $1,950 2026-04-03
Biztalk360 MEDIUM 6.8
CVE-2025-59709

An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User at…

Fix: 11.6.3963.2611+
Fix from $1,600 2026-04-03
Unclassified HIGH 8.1
CVE-2026-4350

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This …

Mitigation only
Fix from $1,950 2026-04-03