Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Fuxa HIGH 7.2
CVE-2026-25951

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an a…

Fix: 1.2.11+
Fix from $1,950 2026-02-09
Fuxa CRITICAL 9.8
CVE-2026-25895EPSS 10%

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
Unclassified HIGH 7.5
CVE-2026-22905

An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/…

Mitigation only
Fix from $1,950 2026-02-09
Unclassified MEDIUM 5.5
CVE-2025-15491

The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate paths passed to include func…

Mitigation only
Fix from $1,600 2026-02-07
Sliver MEDIUM 6.5
CVE-2026-25760

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem l…

Fix: 1.6.11+
Fix from $1,600 2026-02-06
Nicegui HIGH 7.5
CVE-2026-25732

NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitiza…

Fix: 3.7.0+
Fix from $1,950 2026-02-06
Calibre HIGH 8.6
CVE-2026-25635

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere…

Fix: 9.2.0+
Fix from $1,950 2026-02-06
Calibre HIGH 7.8
CVE-2026-25636

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corru…

Fix: 9.2.0+
Fix from $1,950 2026-02-06
Unclassified CRITICAL 9.9
CVE-2026-25592

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerab…

Patch available
Fix from $2,300 2026-02-06
Pydantic Ai MEDIUM 5.4
CVE-2026-25640

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal v…

Fix: 1.51.0+
Fix from $1,600 2026-02-06
Gogs HIGH 8.1
CVE-2026-24135

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of …

Fix: 0.13.4+
Fix from $1,950 2026-02-06
Gogs MEDIUM 6.5
CVE-2026-23633

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook edi…

Fix: 0.13.4+
Fix from $1,600 2026-02-06
My Teditor MEDIUM 5.5
CVE-2025-69619

A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

No fix yet
Fix from $1,600 2026-02-05
Unclassified HIGH 8.7
CVE-2026-1523

Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vulnerability allows an attacker …

Mitigation only
Fix from $1,950 2026-02-05
Siyuan HIGH 7.2
CVE-2026-25539

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allow…

Fix: after 3.5.3
Fix from $1,950 2026-02-04
Navigatum HIGH 7.5
CVE-2026-25575

NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in t…

Fix: 2026-02-03+
Fix from $1,950 2026-02-04
Terraform Provider HIGH 7.5
CVE-2026-25499

Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudo…

Fix: 0.93.1+
Fix from $1,950 2026-02-04
Openclaw MEDIUM 6.5
CVE-2026-25475

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths includ…

Fix: 2026.1.30+
Fix from $1,600 2026-02-04
Melange MEDIUM 5.5
CVE-2026-25145

melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange…

Fix: 0.40.5+
Fix from $1,600 2026-02-04
Alist HIGH 8.8
CVE-2026-25161

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path trav…

Fix: 3.57.0+
Fix from $1,950 2026-02-04
Melange HIGH 8.4
CVE-2026-24843

melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar str…

Fix: 0.40.5+
Fix from $1,950 2026-02-04
Apko HIGH 7.5
CVE-2026-25121

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerabil…

Fix: 1.1.1+
Fix from $1,950 2026-02-04
Unstructured CRITICAL 9.8
CVE-2025-64712

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a…

Fix: 0.18.18+
Fix from $2,300 2026-02-04
N8n HIGH 8.1
CVE-2026-25055

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to …

Fix: 1.123.12 / 2.4.0f+
Fix from $1,950 2026-02-04
Coto MEDIUM 6.5
CVE-2025-69618

An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical interna…

No fix yet
Fix from $1,600 2026-02-04
Android MEDIUM 6.0
CVE-2026-20982

Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.

Mitigation only
Fix from $1,600 2026-02-04
Members MEDIUM 5.5
CVE-2026-20986

Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.

Fix: 15.5.05.4+
Fix from $1,600 2026-02-04
Unclassified HIGH 8.1
CVE-2025-69621

An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to overwrite critical internal fil…

Mitigation only
Fix from $1,950 2026-02-04
Office Reader MEDIUM 5.0
CVE-2025-69620

A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

No fix yet
Fix from $1,600 2026-02-04
Bolo Solo CRITICAL 9.8
CVE-2026-1812

A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/so…

Fix: after 2.6.4
Fix from $2,300 2026-02-03