Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Fireshare CRITICAL 9.1
CVE-2026-34745

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/up…

Fix: 1.5.3+
Fix from $2,300 2026-04-02
Copier MEDIUM 5.5
CVE-2026-34730

Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load Y…

Fix: 9.14.1+
Fix from $1,600 2026-04-02
Poetry MEDIUM 6.5
CVE-2026-34591

Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to di…

Fix: 2.3.3+
Fix from $1,600 2026-04-02
Sillytavern HIGH 8.1
CVE-2026-34522

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Fix: 1.17.0+
Fix from $1,950 2026-04-02
Sillytavern MEDIUM 5.3
CVE-2026-34523

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Fix: 1.17.0+
Fix from $1,600 2026-04-02
Sillytavern HIGH 8.8
CVE-2026-34524

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Fix: 1.17.0+
Fix from $1,950 2026-04-02
Unclassified MEDIUM 6.3
CVE-2026-5344

A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt_uploadImage of the file rpc/…

Mitigation only
Fix from $1,600 2026-04-02
Firewall Community HIGH 8.1
CVE-2026-34790

Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter …

Fix: after 3.3.25
Fix from $1,950 2026-04-02
Phpmyfaq HIGH 8.1
CVE-2026-34728

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the medi…

Fix: 4.1.1+
Fix from $1,950 2026-04-02
Unclassified HIGH 8.1
CVE-2026-4347

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' …

Mitigation only
Fix from $1,950 2026-04-02
Fireware HIGH 7.2
CVE-2026-3987

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execut…

Fix: 12.12 / 2026.2+
Fix from $1,950 2026-04-01
Payload MEDIUM 6.5
CVE-2026-34750

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, …

Fix: 3.78.0+
Fix from $1,600 2026-04-01
Onnx MEDIUM 5.5
CVE-2026-34446

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.loa…

Fix: 1.21.0+
Fix from $1,600 2026-04-01
Onnx MEDIUM 5.5
CVE-2026-34447

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal …

Fix: 1.21.0+
Fix from $1,600 2026-04-01
Onnx HIGH 7.5
CVE-2026-27489

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerabilit…

Fix: 1.21.0+
Fix from $1,950 2026-04-01
Tinacms\/cli HIGH 8.3
CVE-2026-34603

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media rout…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Tinacms\/graphql HIGH 8.8
CVE-2026-34604

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge.…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Tinacms\/graphql HIGH 8.1
CVE-2026-33949

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Secure Connect Gateway HIGH 7.2
CVE-2026-27101

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper Limitation of a Pathname …

Fix: 5.34.00.00+
Fix from $1,950 2026-04-01
Powerstoreos HIGH 7.1
CVE-2026-28265

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this v…

Fix: 4.4.0.0-2692403+
Fix from $1,950 2026-04-01
Unclassified HIGH 7.3
CVE-2026-5258

A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the compon…

Mitigation only
Fix from $1,950 2026-04-01
Claude Sdk For Typescript MEDIUM 5.4
CVE-2026-34451

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before ver…

Fix: 0.81.0+
Fix from $1,600 2026-03-31
Zora CRITICAL 9.8
CVE-2026-30285

An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the fil…

Mitigation only
Fix from $2,300 2026-03-31
Intouch Contacts \& Caller Id HIGH 8.4
CVE-2026-30290

An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the f…

No fix yet
Fix from $1,950 2026-03-31
My Location HIGH 8.4
CVE-2026-30279

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files …

Mitigation only
Fix from $1,950 2026-03-31
Cast To Tv CRITICAL 9.0
CVE-2026-30282

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files vi…

Mitigation only
Fix from $2,300 2026-03-31
Animal Sounds And Ringtones CRITICAL 9.8
CVE-2026-30283

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal fi…

Mitigation only
Fix from $2,300 2026-03-31
Zefiro CRITICAL 9.8
CVE-2026-30286

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via t…

Mitigation only
Fix from $2,300 2026-03-31
Mobile Print HIGH 8.4
CVE-2026-30277

An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal file…

Mitigation only
Fix from $1,950 2026-03-31
Fly Is Fun CRITICAL 9.8
CVE-2026-30278

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file…

Mitigation only
Fix from $2,300 2026-03-31