Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Monitoring CRITICAL 9.8
CVE-2026-32771

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces).…

Fix: 0.2.2+
Fix from $2,300 2026-03-20
Filebrowser MEDIUM 6.5
CVE-2026-32758

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…

Fix: 2.62.0+
Fix from $1,600 2026-03-20
Spring Framework MEDIUM 5.9
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of co…

Fix: 5.3.47 / 6.1.26+
Fix from $1,600 2026-03-20
Siyuan MEDIUM 6.8
CVE-2026-32750

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly t…

Fix: 3.6.1+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.2
CVE-2026-32036

OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authenticatio…

Fix: 2026.2.6+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.5
CVE-2026-32030

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths w…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32033

OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundar…

Fix: 2026.2.24+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.6
CVE-2026-32026

OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 5.5
CVE-2026-32020

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-r…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.1
CVE-2026-32007

OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox a…

Fix: 2026.2.23+
Fix from $1,950 2026-03-19
Siyuan CRITICAL 9.1
CVE-2026-32749

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploa…

Fix: 3.6.1+
Fix from $2,300 2026-03-19
Openemr MEDIUM 6.5
CVE-2026-25928

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export featu…

Fix: 8.0.0.2+
Fix from $1,600 2026-03-19
Unclassified MEDIUM 6.5
CVE-2025-67115

A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows …

Mitigation only
Fix from $1,600 2026-03-19
Wgcloud HIGH 7.5
CVE-2026-30403

There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can …

Fix: after 3.6.3
Fix from $1,950 2026-03-19
Unclassified HIGH 7.5
CVE-2026-3029

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

Patch available
Fix from $1,950 2026-03-19
Unclassified CRITICAL 10.0
CVE-2026-22557EPSS 28%

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t…

Mitigation only
Fix from $2,300 2026-03-19
Romeo HIGH 7.5
CVE-2026-32805

Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with…

Fix: 0.2.2+
Fix from $1,950 2026-03-18
Import Export CRITICAL 9.9
CVE-2026-32731

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `…

Fix: 3.5.3+
Fix from $2,300 2026-03-18
Mlflow CRITICAL 9.1
CVE-2025-15031

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,…

Fix: after 3.10.1
Fix from $2,300 2026-03-18
Jenkins HIGH 8.8
CVE-2026-33001

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing…

Fix: 2.541.3 / 2.555+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 5.5
CVE-2026-27522

OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxR…

Fix: 2026.2.24+
Fix from $1,600 2026-03-18
Openclaw HIGH 7.5
CVE-2026-27523

OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path check…

Fix: 2026.2.24+
Fix from $1,950 2026-03-18
Openclaw CRITICAL 9.1
CVE-2026-22171

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol…

Fix: 2026.2.19+
Fix from $2,300 2026-03-18
Ray HIGH 7.5
CVE-2026-32981

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and san…

Fix: 2.8.1+
Fix from $1,950 2026-03-17
Wazuh HIGH 7.2
CVE-2026-25770

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, …

Fix: 4.14.3+
Fix from $1,950 2026-03-17
Linux MEDIUM 5.5
CVE-2026-21991

A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.

Mitigation only
Fix from $1,600 2026-03-16
Unclassified HIGH 8.7
CVE-2026-29522

ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoin…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.5
CVE-2025-66687

Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files

Mitigation only
Fix from $1,950 2026-03-16
Unraid HIGH 7.3
CVE-2026-3839

Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication…

Mitigation only
Fix from $1,950 2026-03-16
Unraid HIGH 8.8
CVE-2026-3838

Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…

Mitigation only
Fix from $1,950 2026-03-16