Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 6.5
CVE-2026-1793

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the…

Mitigation only
Fix from $1,600 2026-02-15
Lakefs HIGH 8.1
CVE-2026-26187

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/…

Fix: 1.77.0+
Fix from $1,950 2026-02-13
Bacnet Stack HIGH 7.5
CVE-2026-21878

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet…

Patch available
Fix from $1,950 2026-02-13
Unclassified CRITICAL 10.0
CVE-2025-69770

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via upl…

Mitigation only
Fix from $2,300 2026-02-13
Unclassified HIGH 7.5
CVE-2019-25333

Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipu…

No fix yet
Fix from $1,950 2026-02-12
Crawl4ai HIGH 7.5
CVE-2026-26217

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /…

Fix: 0.8.0+
Fix from $1,950 2026-02-12
Dna HIGH 7.5
CVE-2025-15577

An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA We…

Fix: after 2022
Fix from $1,950 2026-02-12
macOS MEDIUM 5.5
CVE-2026-20669

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may b…

Fix: 26.3+
Fix from $1,600 2026-02-11
Ipados MEDIUM 5.5
CVE-2026-20653

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, …

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Safari HIGH 7.5
CVE-2026-20660

A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, …

Fix: 14.8.4 / 18.7.5+
Fix from $1,950 2026-02-11
Ipados HIGH 7.8
CVE-2026-20615

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.…

Fix: 14.8.4 / 26.3+
Fix from $1,950 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20625

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS So…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
macOS HIGH 7.8
CVE-2026-20614

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An …

Fix: 14.8.4 / 15.7.4+
Fix from $1,950 2026-02-11
Unclassified MEDIUM 5.3
CVE-2025-64074

A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete ar…

Mitigation only
Fix from $1,600 2026-02-11
macOS MEDIUM 5.5
CVE-2025-43417

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app m…

Fix: 14.8.4+
Fix from $1,600 2026-02-11
Ipados MEDIUM 5.5
CVE-2025-43537

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restorin…

Fix: 18.7.5+
Fix from $1,600 2026-02-11
Outline MEDIUM 5.5
CVE-2026-25062

Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from…

Fix: 1.4.0+
Fix from $1,600 2026-02-11
Unclassified HIGH 7.5
CVE-2020-37214

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path para…

No fix yet
Fix from $1,950 2026-02-11
Opensatkit HIGH 7.5
CVE-2025-70084

Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted …

Mitigation only
Fix from $1,950 2026-02-11
Nanotar CRITICAL 9.8
CVE-2025-69874

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outsi…

Fix: after 0.2.0
Fix from $2,300 2026-02-11
Minigal Nano HIGH 7.5
CVE-2026-25869

MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-control…

Fix: after 0.3.5
Fix from $1,950 2026-02-11
Unclassified CRITICAL 10.0
CVE-2025-64075

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass au…

Mitigation only
Fix from $2,300 2026-02-11
File Station MEDIUM 6.5
CVE-2025-66278

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.5.6.5190+
Fix from $1,600 2026-02-11
Qsync Central MEDIUM 6.5
CVE-2025-68406

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.4+
Fix from $1,600 2026-02-11
File Station MEDIUM 6.5
CVE-2026-22894

A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.5.6.5190+
Fix from $1,600 2026-02-11
File Station MEDIUM 6.5
CVE-2025-62853

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: 5.5.6.5190+
Fix from $1,600 2026-02-11
Qsync Central MEDIUM 6.5
CVE-2025-58470

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.4+
Fix from $1,600 2026-02-11
Unclassified MEDIUM 5.3
CVE-2026-25872

JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The a…

Mitigation only
Fix from $1,600 2026-02-10
Siyuan HIGH 7.5
CVE-2026-25992

SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block …

Fix: 3.5.5+
Fix from $1,950 2026-02-10
Tapo C260 Firmware HIGH 7.8
CVE-2026-0651

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET request…

Fix: 1.1.9+
Fix from $1,950 2026-02-10