Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.7
CVE-2025-68862

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File Dropzone woo-file-dropzone a…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.5
CVE-2025-68002

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map open-user-map allows Path Tr…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified MEDIUM 6.5
CVE-2025-59819

This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an internal system path.

Mitigation only
Fix from $1,600 2026-02-20
Calibre HIGH 8.8
CVE-2026-26065

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path …

Fix: 9.3.0+
Fix from $1,950 2026-02-20
Tar HIGH 7.1
CVE-2026-26960

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hard…

Fix: 7.5.8+
Fix from $1,950 2026-02-20
Calibre HIGH 8.8
CVE-2026-26064

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversa…

Fix: 9.3.0+
Fix from $1,950 2026-02-20
Music Assistant Server HIGH 8.8
CVE-2026-26975

Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow un…

Fix: 2.7.0+
Fix from $1,950 2026-02-20
Openclaw MEDIUM 6.7
CVE-2026-26972

OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. …

Fix: 2026.2.13+
Fix from $1,600 2026-02-20
Openclaw MEDIUM 6.5
CVE-2026-26329

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying …

Fix: 2026.2.14+
Fix from $1,600 2026-02-20
Openclaw HIGH 7.5
CVE-2026-26321

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Xm Fax HIGH 7.5
CVE-2025-8054

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal.  The vulnera…

Mitigation only
Fix from $1,950 2026-02-19
Penpot HIGH 7.5
CVE-2026-26202

Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from …

Fix: 2.13.2+
Fix from $1,950 2026-02-19
Echo MEDIUM 5.3
CVE-2026-25766

Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal…

Fix: 5.0.3+
Fix from $1,600 2026-02-19
Changedetection MEDIUM 5.3
CVE-2026-25527

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts …

Fix: 0.53.2+
Fix from $1,600 2026-02-19
Unclassified CRITICAL 10.0
CVE-2026-2731

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers t…

Mitigation only
Fix from $2,300 2026-02-19
Cyreneadmin MEDIUM 6.5
CVE-2026-2692

A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component…

Fix: after 1.3.0
Fix from $1,600 2026-02-19
Electronic Archives System MEDIUM 5.3
CVE-2026-2672

A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function…

Fix: after 3.2.210802
Fix from $1,600 2026-02-18
Unclassified HIGH 7.5
CVE-2019-25352

Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL pa…

No fix yet
Fix from $1,950 2026-02-18
Gsoap HIGH 7.5
CVE-2019-25355

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path travers…

No fix yet
Fix from $1,950 2026-02-18
Invoiceplane HIGH 7.5
CVE-2026-23491

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get…

Fix: 1.6.4+
Fix from $1,950 2026-02-18
Rack HIGH 7.5
CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match o…

Fix: 2.2.22 / 3.1.20+
Fix from $1,950 2026-02-18
Splunk MEDIUM 5.7
CVE-2026-20137

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2…

Fix: 9.2.9 / 9.3.7+
Fix from $1,600 2026-02-18
Unclassified HIGH 8.7
CVE-2026-2464

Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read arbitrary files from the unde…

Mitigation only
Fix from $1,950 2026-02-18
Unclassified MEDIUM 6.5
CVE-2026-2426

The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in th…

Patch available
Fix from $1,600 2026-02-18
Blossom HIGH 8.8
CVE-2026-2623

A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/common-iaas/src/main/java/com/b…

Fix: after 1.17.1
Fix from $1,950 2026-02-17
Unclassified MEDIUM 6.5
CVE-2026-22762

Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitation of a Pathname to a Restrict…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified MEDIUM 6.5
CVE-2025-36598

Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vu…

Mitigation only
Fix from $1,600 2026-02-17
Unclassified HIGH 8.8
CVE-2025-12062

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion i…

Mitigation only
Fix from $1,950 2026-02-17
Zentao MEDIUM 5.5
CVE-2026-2552

A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component …

Fix: after 21.7.8
Fix from $1,600 2026-02-16
Zentao MEDIUM 5.4
CVE-2026-2551

A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the co…

Fix: after 21.7.8
Fix from $1,600 2026-02-16