Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Wisp HIGH 7.5
CVE-2026-28807

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows arbitrary file read via percen…

Fix: 2.2.1+
Fix from $1,950 2026-03-10
Liquidjs HIGH 7.5
CVE-2026-30952

liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render, and include tags allow arbi…

Fix: 10.25.0+
Fix from $1,950 2026-03-10
Mcp Atlassian HIGH 8.0
CVE-2026-27825

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_downloa…

Fix: 0.17.0+
Fix from $1,950 2026-03-10
Appium\/support MEDIUM 6.5
CVE-2026-30973

Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Prior to 7.0.6, @appium/support …

Fix: 7.0.6+
Fix from $1,600 2026-03-10
Flare MEDIUM 6.5
CVE-2026-30942

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an authenticated path traversal …

Fix: 1.7.3+
Fix from $1,600 2026-03-10
Oneuptime HIGH 8.6
CVE-2026-30958

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:compo…

Fix: 10.0.21+
Fix from $1,950 2026-03-10
Vaadin MEDIUM 6.8
CVE-2026-2741

Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, …

Fix: 14.14.1 / 23.6.7+
Fix from $1,600 2026-03-10
Pdfbox MEDIUM 5.3
CVE-2026-23907

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFil…

Fix: after 3.0.7
Fix from $1,600 2026-03-10
Fortisoar Agent Communication Bridge HIGH 7.5
CVE-2025-54659

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Co…

Mitigation only
Fix from $1,950 2026-03-10
Unclassified HIGH 7.5
CVE-2026-3585

The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_impor…

Mitigation only
Fix from $1,950 2026-03-10
Siyuan CRITICAL 9.8
CVE-2026-30869

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read …

Fix: 3.5.10+
Fix from $2,300 2026-03-10
Tar MEDIUM 5.5
CVE-2026-31802

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extrac…

Fix: 7.5.11+
Fix from $1,600 2026-03-10
Camaleon Cms MEDIUM 6.5
CVE-2026-1776

Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation th…

Fix: after 2.9.0
Fix from $1,600 2026-03-10
Budibase HIGH 8.1
CVE-2026-30240

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in th…

Fix: after 3.31.5
Fix from $1,950 2026-03-09
Sunbirded Portal HIGH 7.5
CVE-2025-70028

An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-…

Mitigation only
Fix from $1,950 2026-03-09
Nltk HIGH 7.5
CVE-2026-0846

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation …

No fix yet
Fix from $1,950 2026-03-09
Actual MEDIUM 6.5
CVE-2026-3089

Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation o…

Fix: 26.3.0+
Fix from $1,600 2026-03-09
Universal Bacnet Router Firmware MEDIUM 6.5
CVE-2025-41755

A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a param…

Fix: 6.0.1.0+
Fix from $1,600 2026-03-09
Universal Bacnet Router Firmware HIGH 8.8
CVE-2025-41757

A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not val…

Fix: 6.0.1.0+
Fix from $1,950 2026-03-09
Universal Bacnet Router Firmware HIGH 8.8
CVE-2025-41758

A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead …

Fix: 6.0.1.0+
Fix from $1,950 2026-03-09
Doracms CRITICAL 9.8
CVE-2026-3795

A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v…

Mitigation only
Fix from $2,300 2026-03-09
Unclassified MEDIUM 5.3
CVE-2026-3719

A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the f…

Mitigation only
Fix from $1,600 2026-03-08
Modern Image Gallery App MEDIUM 6.5
CVE-2026-3695

A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipula…

No fix yet
Fix from $1,600 2026-03-08
Eml Parser MEDIUM 5.5
CVE-2026-29780

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Pri…

Fix: 2.0.1+
Fix from $1,600 2026-03-07
Tar MEDIUM 6.3
CVE-2026-29786

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction …

Fix: 7.5.10+
Fix from $1,600 2026-03-07
Karapace MEDIUM 5.3
CVE-2026-29190

Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Traversal vulnerability in the b…

Fix: 6.0.0+
Fix from $1,600 2026-03-07
Unclassified HIGH 7.2
CVE-2025-14675

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' functio…

Patch available
Fix from $1,950 2026-03-07
Wallos HIGH 7.5
CVE-2026-30828

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system…

Fix: 4.6.2+
Fix from $1,950 2026-03-07
Dbt Common MEDIUM 5.3
CVE-2026-29790

dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnera…

Fix: 1.34.2 / 1.37.3+
Fix from $1,600 2026-03-06
Zarf HIGH 8.2
CVE-2026-29064

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive ext…

Fix: 0.73.1+
Fix from $1,950 2026-03-06