Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Dart Software Development Kit HIGH 7.5
CVE-2026-27704

The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Fl…

Fix: 3.11.0 / 3.41.0+
Fix from $1,950 2026-02-25
Basic Ftp CRITICAL 9.8
CVE-2026-27699

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` m…

Fix: 5.2.0+
Fix from $2,300 2026-02-25
Octopus Server CRITICAL 9.1
CVE-2026-0704

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va…

Fix: 2025.3.14715+
Fix from $2,300 2026-02-25
Data Master HIGH 8.1
CVE-2026-3179

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…

Fix: 5.1.2.reo1+
Fix from $1,950 2026-02-25
Lanscope Endpoint Manager CRITICAL 9.8
CVE-2026-25785

Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacke…

Fix: 9.4.8.0+
Fix from $2,300 2026-02-25
Flask Reuploaded CRITICAL 9.8
CVE-2026-27641

Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remo…

Fix: 1.5.0+
Fix from $2,300 2026-02-25
Rollup CRITICAL 9.8
CVE-2026-27606

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present i…

Fix: 2.80.0 / 3.30.0+
Fix from $2,300 2026-02-25
Openemr MEDIUM 6.5
CVE-2026-24849

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument…

Fix: 7.0.4+
Fix from $1,600 2026-02-25
Dagu MEDIUM 6.5
CVE-2026-27598

Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/…

Fix: after 1.16.7
Fix from $1,600 2026-02-25
Bit7z HIGH 7.5
CVE-2026-27117

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulne…

Fix: 4.0.11+
Fix from $1,950 2026-02-24
Fiber HIGH 7.5
CVE-2026-25891

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the sta…

Fix: 3.1.0+
Fix from $1,950 2026-02-24
Mr9600 Firmware MEDIUM 6.6
CVE-2026-25603

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents o…

No fix yet
Fix from $1,600 2026-02-24
Mindsdb HIGH 8.8
CVE-2026-27483EPSS 11%

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability i…

Fix: 25.9.1.1+
Fix from $1,950 2026-02-24
Muyucms HIGH 7.2
CVE-2025-15589

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the …

No fix yet
Fix from $1,950 2026-02-24
Hummerrisk HIGH 8.8
CVE-2026-3067

A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-co…

Fix: after 1.5.0
Fix from $1,950 2026-02-24
Imagemagick HIGH 7.5
CVE-2026-25965

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-24
Dinky HIGH 7.6
CVE-2026-3051EPSS 6%

A vulnerability has been found in DataLinkDC dinky up to 1.2.5. The affected element is the function getProjectDir of the file dinky-admin/src/main/j…

Fix: after 1.2.5
Fix from $1,950 2026-02-24
Traccar MEDIUM 6.5
CVE-2026-23521

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or ed…

Fix: after 6.11.1
Fix from $1,600 2026-02-23
Ujcms CRITICAL 9.1
CVE-2026-2953

A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o…

No fix yet
Fix from $2,300 2026-02-22
Unclassified MEDIUM 5.4
CVE-2026-2864

A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the func…

Mitigation only
Fix from $1,600 2026-02-21
Unclassified MEDIUM 5.4
CVE-2026-2863

A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the fu…

Mitigation only
Fix from $1,600 2026-02-21
Getsimple Cms HIGH 7.5
CVE-2026-27202

GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file …

No fix yet
Fix from $1,950 2026-02-21
Unclassified HIGH 7.3
CVE-2026-2033

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Patch available
Fix from $1,950 2026-02-20
Adb Explorer HIGH 7.1
CVE-2026-27115

ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigge…

Fix: 0.9.26021+
Fix from $1,950 2026-02-20
Unclassified HIGH 8.2
CVE-2026-2818

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended ext…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.5
CVE-2026-24953

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list all…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 8.6
CVE-2025-69376

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allow…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.7
CVE-2025-69377

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allow…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.6
CVE-2025-69379

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhe…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2025-69380

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhe…

Mitigation only
Fix from $1,950 2026-02-20