Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Blinko HIGH 7.5
CVE-2026-23482

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ pa…

Fix: 1.8.4+
Fix from $1,950 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23483

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths …

Fix: 1.8.3+
Fix from $1,600 2026-03-23
Blinko MEDIUM 6.5
CVE-2026-23484

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal t…

Fix: 1.8.3+
Fix from $1,600 2026-03-23
Blinko MEDIUM 5.3
CVE-2026-23485

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumerati…

Fix: 1.8.4+
Fix from $1,600 2026-03-23
Avideo HIGH 7.2
CVE-2026-33681

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.5
CVE-2026-33513

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates u…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.1
CVE-2026-33493

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled …

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.5
CVE-2026-33292

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal at…

Fix: 26.0+
Fix from $1,950 2026-03-22
Avideo HIGH 8.1
CVE-2026-33293

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed …

Fix: 26.0+
Fix from $1,950 2026-03-22
Unclassified MEDIUM 6.5
CVE-2019-25610

NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files …

No fix yet
Fix from $1,600 2026-03-22
Unclassified MEDIUM 5.4
CVE-2026-4542

A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the componen…

Mitigation only
Fix from $1,600 2026-03-22
Seotoaster MEDIUM 5.5
CVE-2019-25577

SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arbitrary files by manipulating …

Fix: after 3.0.0
Fix from $1,600 2026-03-21
Phptransformer HIGH 7.5
CVE-2019-25579

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating th…

No fix yet
Fix from $1,950 2026-03-21
Greencms MEDIUM 6.5
CVE-2019-25574

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting di…

Fix: after 2.3.0603
Fix from $1,600 2026-03-21
Openclaw HIGH 8.2
CVE-2026-32055

OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files out…

Fix: 2026.2.26+
Fix from $1,950 2026-03-21
Siyuan HIGH 7.5
CVE-2026-33476

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/…

Fix: 3.6.2+
Fix from $1,950 2026-03-20
Unclassified MEDIUM 6.5
CVE-2026-3864

A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. At…

No fix yet
Fix from $1,600 2026-03-20
Nltk HIGH 8.1
CVE-2026-33236

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…

Fix: after 3.9.3
Fix from $1,950 2026-03-20
Siyuan MEDIUM 6.8
CVE-2026-33194

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/util/path.go` uses a denylist a…

Fix: 3.6.2+
Fix from $1,600 2026-03-20
Halloy MEDIUM 6.5
CVE-2026-32733

Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive flow did not sanitize filenam…

Fix: after 2026.4
Fix from $1,600 2026-03-20
Allure Report HIGH 7.5
CVE-2026-33166

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vul…

Fix: 2.38.0+
Fix from $1,950 2026-03-20
Unclassified HIGH 7.5
CVE-2026-23536

A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any fi…

Mitigation only
Fix from $1,950 2026-03-20
Dreamfactory Core HIGH 7.2
CVE-2025-55988

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsani…

Patch available
Fix from $1,950 2026-03-20
Cryptomator MEDIUM 5.3
CVE-2026-32310

Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its…

Fix: after 1.19.0
Fix from $1,600 2026-03-20
Unclassified MEDIUM 6.5
CVE-2026-2421

The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the 'c…

Mitigation only
Fix from $1,600 2026-03-20
Stirling Pdf MEDIUM 6.5
CVE-2026-27625

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markd…

Fix: 2.5.2+
Fix from $1,600 2026-03-20
Mesop CRITICAL 9.8
CVE-2026-33054

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability tha…

Fix: 1.2.3+
Fix from $2,300 2026-03-20
Siyuan MEDIUM 6.5
CVE-2026-32938

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed …

Fix: 3.6.1+
Fix from $1,600 2026-03-20
Pyload Ng HIGH 8.1
CVE-2026-32808

pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password v…

Fix: 0.5.0b3.dev97+
Fix from $1,950 2026-03-20
Pydicom HIGH 7.8
CVE-2026-32711

pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a malicious…

Fix: 3.0.2+
Fix from $1,950 2026-03-20