Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Px4 Drone Autopilot MEDIUM 6.8
CVE-2026-32709

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVL…

Fix: 1.17.0+
Fix from $1,600 2026-03-16
Anythingllm MEDIUM 6.4
CVE-2026-32719

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th…

Fix: after 1.11.1
Fix from $1,600 2026-03-16
Unclassified HIGH 7.5
CVE-2026-2493

IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive info…

Mitigation only
Fix from $1,950 2026-03-16
Galaxy Store MEDIUM 5.5
CVE-2026-21000

Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

Fix: 4.6.03.8+
Fix from $1,600 2026-03-16
Galaxy Store MEDIUM 5.5
CVE-2026-21001

Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

Fix: 4.6.03.8+
Fix from $1,600 2026-03-16
Smart Switch MEDIUM 6.5
CVE-2026-21005

Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

Fix: 3.7.69.15+
Fix from $1,600 2026-03-16
Clasp HIGH 8.8
CVE-2026-4092

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script proje…

Fix: 3.2.0+
Fix from $1,950 2026-03-13
Dagu HIGH 7.6
CVE-2026-31886

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoin…

Fix: 2.2.4+
Fix from $1,950 2026-03-13
Calibre HIGH 8.2
CVE-2026-30853

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability i…

Fix: 9.5.0+
Fix from $1,950 2026-03-13
Sftpgo HIGH 8.1
CVE-2026-30914

SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protoc…

Fix: 2.7.1+
Fix from $1,950 2026-03-13
Erlang\/otp MEDIUM 5.4
CVE-2026-23942

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. …

Fix: 5.1.4.14 / 5.2.11.6+
Fix from $1,600 2026-03-13
Wpdiscuz HIGH 7.5
CVE-2026-22199

Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenti…

Fix: 7.6.47+
Fix from $1,950 2026-03-13
Livy MEDIUM 6.3
CVE-2025-66249

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.…

Fix: 0.9.0+
Fix from $1,600 2026-03-13
Black HIGH 7.5
CVE-2026-32274

Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of whi…

Fix: 26.3.1+
Fix from $1,950 2026-03-12
Zeptoclaw CRITICAL 9.8
CVE-2026-32232

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink A…

Fix: after 0.7.5
Fix from $2,300 2026-03-12
Dataease HIGH 8.8
CVE-2026-32140

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC d…

Fix: 2.10.20+
Fix from $1,950 2026-03-12
Magic Wormhole HIGH 8.1
CVE-2026-32116

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a…

Fix: 0.23.0+
Fix from $1,950 2026-03-12
Tinacms\/cli HIGH 7.4
CVE-2026-28791

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload …

Fix: 2.1.7+
Fix from $1,950 2026-03-12
Tinacms\/cli CRITICAL 9.6
CVE-2026-28792

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al…

Fix: 2.1.8+
Fix from $2,300 2026-03-12
Tinacms\/cli HIGH 8.4
CVE-2026-28793

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path …

Fix: 2.1.8+
Fix from $1,950 2026-03-12
Tinacms\/graphql MEDIUM 6.3
CVE-2026-24125

Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative fil…

Fix: 2.1.2+
Fix from $1,600 2026-03-12
Unclassified MEDIUM 6.5
CVE-2026-3954

A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application…

Mitigation only
Fix from $1,600 2026-03-11
Unclassified HIGH 7.5
CVE-2019-25480

ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulati…

No fix yet
Fix from $1,950 2026-03-11
File Thingie CRITICAL 9.8
CVE-2019-25471

FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the…

Fix: after 2.5.7
Fix from $2,300 2026-03-11
Openproject MEDIUM 6.5
CVE-2026-30234

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions ca…

Fix: 17.2.0+
Fix from $1,600 2026-03-11
Vociferous HIGH 7.1
CVE-2026-27897

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py wi…

Fix: 4.4.2+
Fix from $1,950 2026-03-11
Unclassified HIGH 8.7
CVE-2026-3013

Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vuln…

Mitigation only
Fix from $1,950 2026-03-11
Openclaw HIGH 8.8
CVE-2026-32060

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the…

Fix: 2026.2.14+
Fix from $1,950 2026-03-11
Commerce MEDIUM 6.8
CVE-2026-21360

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pat…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Olivetin HIGH 8.5
CVE-2026-31817

OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists …

Fix: 3000.11.2+
Fix from $1,950 2026-03-10