Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Openclaw HIGH 7.5
CVE-2026-32846

OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path va…

Fix: after 2026.3.23
Fix from $1,950 2026-03-26
Small Http Server HIGH 8.1
CVE-2025-41368

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended re…

Fix: 3.06.38+
Fix from $1,950 2026-03-26
Saloon CRITICAL 9.1
CVE-2026-33183

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file path…

Fix: 4.0.0+
Fix from $2,300 2026-03-26
Unclassified HIGH 8.8
CVE-2026-4758

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfie…

Mitigation only
Fix from $1,950 2026-03-26
Sonarr HIGH 7.5
CVE-2026-30976

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potential…

Fix: 4.0.17.2950+
Fix from $1,950 2026-03-25
Pf4j HIGH 7.5
CVE-2025-70952

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow …

Fix: 3.14.1+
Fix from $1,950 2026-03-25
Plexus Utils HIGH 8.8
CVE-2025-67030

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e001…

Fix: 3.6.1 / 4.0.3+
Fix from $1,950 2026-03-25
Unclassified MEDIUM 6.8
CVE-2026-32567

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in icopydoc YML for Yandex Market yml-for-yandex-market …

Mitigation only
Fix from $1,600 2026-03-25
Unclassified HIGH 8.6
CVE-2026-32522

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerc…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 6.8
CVE-2026-32496

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified HIGH 8.6
CVE-2026-31913

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.Thi…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 8.8
CVE-2026-27040

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issu…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 6.8
CVE-2026-25328

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce produ…

Mitigation only
Fix from $1,600 2026-03-25
Unclassified HIGH 7.7
CVE-2026-24969

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Trave…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.7
CVE-2026-24970

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified HIGH 7.5
CVE-2026-22448

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal…

Mitigation only
Fix from $1,950 2026-03-25
macOS CRITICAL 9.3
CVE-2026-28827

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS So…

Fix: 14.8.5 / 15.7.5+
Fix from $2,300 2026-03-25
Ipados CRITICAL 9.3
CVE-2026-20688

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.…

Fix: 14.8.5 / 15.7.5+
Fix from $2,300 2026-03-25
Filerise HIGH 8.1
CVE-2026-33329

FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Res…

Fix: 3.10.0+
Fix from $1,950 2026-03-24
Dagu HIGH 8.1
CVE-2026-33344

Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDA…

Fix: 2.3.1+
Fix from $1,950 2026-03-24
Langflow HIGH 7.5
CVE-2026-33497EPSS 20%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of th…

Fix: 1.7.1+
Fix from $1,950 2026-03-24
Langflow CRITICAL 9.9
CVE-2026-33309EPSS 11%

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6…

Fix: 1.9.0+
Fix from $2,300 2026-03-24
Unclassified HIGH 8.6
CVE-2026-4741

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app/src/main/java/com/rdapps/gam…

Patch available
Fix from $1,950 2026-03-24
Unclassified HIGH 8.6
CVE-2026-22739

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native …

Mitigation only
Fix from $1,950 2026-03-24
Tekton Pipelines CRITICAL 9.6
CVE-2026-33211

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3…

Fix: 1.3.3 / 1.6.1+
Fix from $2,300 2026-03-24
Salvo HIGH 7.5
CVE-2026-33242

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy compon…

Fix: 0.89.3+
Fix from $1,950 2026-03-24
Rails CRITICAL 9.8
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $2,300 2026-03-24
Indico HIGH 8.8
CVE-2026-33046

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to …

Fix: 3.3.12+
Fix from $1,950 2026-03-23
Csweb HIGH 8.8
CVE-2025-60946

Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha.

Patch available
Fix from $1,950 2026-03-23
Blinko MEDIUM 6.5
CVE-2026-23481

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditio…

Fix: 1.8.4+
Fix from $1,600 2026-03-23