Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 6.5
CVE-2026-73033

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integri…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 8.1
CVE-2026-72903

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal file…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.1
CVE-2026-69112

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-12339

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequ…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-47754

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta…

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-15059

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72567

An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or …

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-72569

A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72571

A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from t…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-72572

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.2
CVE-2026-13170

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing user…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19372

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSy…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19371

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the c…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19370

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19366

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the …

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19365

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the compone…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19338

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mc…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19336

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/to…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19335

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the fi…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-18465

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19331

A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/Ca…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19330

A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to …

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19327

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enri…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19328

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninst…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19325

A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19323

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the …

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19288

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of th…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19287

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This m…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19285

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function J…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19270

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_s…

No fix yet
Fix from $1,600 2026-08-08