Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.2
CVE-2018-25194

Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious co…

No fix yet
Fix from $1,950 2026-03-06
Unclassified HIGH 7.5
CVE-2018-25181

Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the par…

No fix yet
Fix from $1,950 2026-03-06
Unclassified MEDIUM 6.2
CVE-2018-25184

Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the …

No fix yet
Fix from $1,600 2026-03-06
Easyndexer HIGH 7.5
CVE-2018-25178

Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating th…

No fix yet
Fix from $1,950 2026-03-06
Windmill HIGH 7.5
CVE-2026-29059

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticat…

Fix: 1.603.3+
Fix from $1,950 2026-03-06
Changedetection CRITICAL 9.1
CVE-2026-29065

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore func…

Fix: 0.54.4+
Fix from $2,300 2026-03-06
Openchatbi CRITICAL 9.8
CVE-2026-28795

OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through n…

Fix: 0.2.2+
Fix from $2,300 2026-03-06
Natro Macro HIGH 8.0
CVE-2026-28800

Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a…

Fix: 1.1.0+
Fix from $1,950 2026-03-06
Opensift HIGH 8.8
CVE-2026-28676

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storag…

Fix: 1.6.3+
Fix from $1,950 2026-03-06
Homegallery HIGH 7.5
CVE-2026-28679

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a downl…

Fix: 1.21.0+
Fix from $1,950 2026-03-06
Talishar HIGH 7.5
CVE-2026-28429

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified in the gameName parameter. Whi…

Fix: 2026-02-22+
Fix from $1,950 2026-03-06
Aci Confidential Containers MEDIUM 6.7
CVE-2026-26124

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,600 2026-03-05
Openclaw HIGH 7.1
CVE-2026-28482

OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing d…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.5
CVE-2026-28486

OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allow…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw HIGH 7.9
CVE-2026-28457

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmat…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28462

OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and …

Fix: 2026.2.13+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28453

OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28447

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin packa…

Fix: 2026.2.1+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28393

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openmq CRITICAL 9.8
CVE-2026-24457

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's…

Fix: after 6.5.1
Fix from $2,300 2026-03-05
Ragas HIGH 7.5
CVE-2025-45691

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems…

Fix: after 0.2.14
Fix from $1,950 2026-03-05
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70231

D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin…

Mitigation only
Fix from $2,300 2026-03-05
Harmonyos MEDIUM 5.5
CVE-2026-28538

Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.

Mitigation only
Fix from $1,600 2026-03-05
Seppmail CRITICAL 9.8
CVE-2026-2743

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf…

Fix: after 15.0.2.1
Fix from $2,300 2026-03-05
Unclassified HIGH 8.6
CVE-2026-22460

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax FormGent formgent allows Path Traversal.This is…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified HIGH 7.5
CVE-2025-69411

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-te…

Mitigation only
Fix from $1,950 2026-03-05
Opendeck HIGH 7.5
CVE-2026-28427

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins…

Fix: 2.8.1+
Fix from $1,950 2026-03-04
Nltk HIGH 7.5
CVE-2026-0847

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including …

Fix: after 3.9.2
Fix from $1,950 2026-03-04
Seppmail HIGH 7.5
CVE-2026-27442

The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, …

Fix: 15.0.1+
Fix from $1,950 2026-03-04
Sfx2100 Firmware MEDIUM 6.5
CVE-2026-28769

A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex …

No fix yet
Fix from $1,600 2026-03-04