Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Openclaw HIGH 8.6
CVE-2026-33581

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using me…

Fix: 2026.3.24+
Fix from $1,950 2026-03-31
Unclassified HIGH 7.6
CVE-2026-29870

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir pa…

Mitigation only
Fix from $1,950 2026-03-31
3dexperience CRITICAL 9.1
CVE-2025-10559

A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Rele…

Mitigation only
Fix from $2,300 2026-03-31
Langchain Core HIGH 7.5
CVE-2026-34070

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.load…

Fix: 1.2.22+
Fix from $1,950 2026-03-31
Scitokens Library MEDIUM 6.5
CVE-2026-32727

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack wh…

Fix: 1.9.7+
Fix from $1,600 2026-03-31
Basercms HIGH 7.2
CVE-2026-30940

baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/a…

Fix: 5.2.3+
Fix from $1,950 2026-03-31
Gotenberg HIGH 7.5
CVE-2026-27018

Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case …

Fix: 8.29.0+
Fix from $1,950 2026-03-30
Nginx Ui MEDIUM 6.5
CVE-2026-33027

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversa…

Fix: 2.3.4+
Fix from $1,600 2026-03-30
Mlflow CRITICAL 10.0
CVE-2025-15036

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf…

Fix: 3.9.0+
Fix from $2,300 2026-03-30
Unclassified MEDIUM 5.3
CVE-2026-5014

A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log/ of the component Wildcard H…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified MEDIUM 5.3
CVE-2026-5013

A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key. The manipulation of the arg…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified MEDIUM 6.3
CVE-2026-4999

A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified MEDIUM 5.3
CVE-2026-4997

A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified HIGH 8.4
CVE-2016-20048

iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized val…

No fix yet
Fix from $1,950 2026-03-28
Unclassified HIGH 8.4
CVE-2016-20040

TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application o…

No fix yet
Fix from $1,950 2026-03-28
Unclassified HIGH 8.4
CVE-2016-20041

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an …

No fix yet
Fix from $1,950 2026-03-28
Mobile Mcp MEDIUM 6.5
CVE-2026-33989

Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Trav…

Fix: 0.0.49+
Fix from $1,600 2026-03-27
Langflow HIGH 8.8
CVE-2026-5027EPSS 33%

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arb…

Fix: 1.9.0+
Fix from $1,950 2026-03-27
Buildkit HIGH 7.5
CVE-2026-33748

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insuf…

Fix: 0.28.1+
Fix from $1,950 2026-03-27
Awesome Llm Apps HIGH 7.5
CVE-2026-29871

A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong …

Fix: 2026-01-19+
Fix from $1,950 2026-03-27
Aterm Wx3600hp Firmware CRITICAL 9.8
CVE-2026-4619

Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

Fix: 1.5.3+
Fix from $2,300 2026-03-27
Dovecot MEDIUM 5.3
CVE-2026-0394

When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowe…

Fix: 2.4.0 / 3.1.0+
Fix from $1,600 2026-03-27
Buildkit CRITICAL 9.8
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when …

Fix: 0.28.1+
Fix from $2,300 2026-03-27
Incus CRITICAL 9.6
CVE-2026-33945

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container…

Fix: 6.23.0+
Fix from $2,300 2026-03-27
Sharp HIGH 8.8
CVE-2026-33686

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil…

Fix: 9.20.0+
Fix from $1,950 2026-03-26
Siyuan HIGH 7.5
CVE-2026-33670

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file …

Fix: 3.6.2+
Fix from $1,950 2026-03-26
Fireshare HIGH 8.1
CVE-2026-33645

Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked uplo…

Mitigation only
Fix from $1,950 2026-03-26
Hardened Images MEDIUM 6.3
CVE-2026-0964

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could…

Fix: 0.11.4+
Fix from $1,600 2026-03-26
Zoraxy HIGH 8.8
CVE-2026-33529

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the conf…

Fix: 3.3.2+
Fix from $1,950 2026-03-26
Godoxy MEDIUM 6.5
CVE-2026-33528

GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API endpoint at `/api/v1/file/conten…

Fix: 0.27.5+
Fix from $1,600 2026-03-26