Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Openemr CRITICAL 9.9
CVE-2026-24848EPSS 6%

OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() …

Fix: 7.0.4+
Fix from $2,300 2026-03-03
Webmethods Api Gateway MEDIUM 6.5
CVE-2026-2606

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to …

Mitigation only
Fix from $1,600 2026-03-03
Openviking HIGH 7.8
CVE-2026-28518

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attac…

Fix: 0.2.1+
Fix from $1,950 2026-03-03
Unclassified HIGH 8.8
CVE-2026-2448

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate…

Mitigation only
Fix from $1,950 2026-03-03
Android HIGH 8.4
CVE-2025-48636

In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could …

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48567

In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode…

Mitigation only
Fix from $1,950 2026-03-02
Deco Be25 Firmware HIGH 8.0
CVE-2026-0655

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authentic…

Fix: after 1.1.1
Fix from $1,950 2026-03-02
Jeesite HIGH 8.1
CVE-2026-3405

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The…

Fix: after 5.15.1
Fix from $1,950 2026-03-02
Gradio HIGH 7.5
CVE-2026-28414

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vul…

Fix: 6.7.0+
Fix from $1,950 2026-02-27
Kaniko HIGH 8.2
CVE-2026-28406

kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to versi…

Fix: 1.25.10+
Fix from $1,950 2026-02-27
Beszel MEDIUM 6.5
CVE-2026-27734

Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/b…

Fix: 0.18.2+
Fix from $1,600 2026-02-27
Openemr MEDIUM 6.5
CVE-2026-24488

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an ar…

Fix: after 8.0.0
Fix from $1,600 2026-02-27
Open Tickets HIGH 8.8
CVE-2026-2749

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on…

Fix: 24.04.7 / 24.10.8+
Fix from $1,950 2026-02-27
Web Designer HIGH 7.8
CVE-2026-3223

Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.

No fix yet
Fix from $1,950 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21659

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q…

Fix: after 10.22
Fix from $2,300 2026-02-27
Freeflow Core CRITICAL 9.8
CVE-2026-2251

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal …

Fix: 8.1.0+
Fix from $2,300 2026-02-27
Publiccms CRITICAL 9.8
CVE-2026-3289

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the…

Mitigation only
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware CRITICAL 9.1
CVE-2026-22877

An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the…

Fix: after 1.12.1
Fix from $2,300 2026-02-27
Junrar MEDIUM 5.9
CVE-2026-28208EPSS 12%

Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows …

Fix: 7.5.8+
Fix from $1,600 2026-02-26
Hexpm HIGH 7.5
CVE-2026-23939

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module)…

Fix: 2026-02-26+
Fix from $1,950 2026-02-26
Unclassified CRITICAL 9.8
CVE-2025-50857

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code v…

Mitigation only
Fix from $2,300 2026-02-26
Unclassified HIGH 8.8
CVE-2026-1311

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functio…

Mitigation only
Fix from $1,950 2026-02-26
Vitess HIGH 8.8
CVE-2026-27969

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…

Fix: 22.0.4 / 23.0.3+
Fix from $1,950 2026-02-26
Unclassified HIGH 7.5
CVE-2026-1557

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This…

Mitigation only
Fix from $1,950 2026-02-26
Unclassified MEDIUM 5.3
CVE-2026-27884

NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file and folder path when saving fi…

Patch available
Fix from $1,600 2026-02-26
Model Context Protocol Servers MEDIUM 6.5
CVE-2026-27735

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…

Fix: 2026.1.14+
Fix from $1,600 2026-02-26
Zed HIGH 7.4
CVE-2026-27800

Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. …

Fix: 0.224.4+
Fix from $1,950 2026-02-26
Vikunja HIGH 7.2
CVE-2026-27819

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restor…

Fix: 2.0.0+
Fix from $1,950 2026-02-25
Loris HIGH 8.8
CVE-2026-26984

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: 26.0.5 / 27.0.2+
Fix from $1,950 2026-02-25
Loris MEDIUM 6.5
CVE-2026-26985

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: 26.0.5 / 27.0.2+
Fix from $1,600 2026-02-25