Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Bolo Solo HIGH 8.8
CVE-2026-1811

A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/…

Fix: after 2.6.4
Fix from $1,950 2026-02-03
Unclassified MEDIUM 6.2
CVE-2020-37086

Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system…

No fix yet
Fix from $1,600 2026-02-03
School Erp Pro HIGH 7.5
CVE-2020-37088

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'docume…

No fix yet
Fix from $1,950 2026-02-03
Unclassified MEDIUM 6.5
CVE-2020-37077

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators…

No fix yet
Fix from $1,600 2026-02-03
Claude Code MEDIUM 6.5
CVE-2026-24053

Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible …

Fix: 2.0.74+
Fix from $1,600 2026-02-03
Bolo Solo HIGH 8.8
CVE-2026-1810

A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org…

Fix: after 2.6.4
Fix from $1,950 2026-02-03
Unclassified HIGH 8.8
CVE-2025-65077

A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be…

Mitigation only
Fix from $1,950 2026-02-03
Mediawiki MEDIUM 5.4
CVE-2025-61646

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. …

Fix: 1.39.14 / 1.43.4+
Fix from $1,600 2026-02-03
Mediawiki MEDIUM 6.1
CVE-2025-61641

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php. This issue a…

Fix: 1.39.14 / 1.43.4+
Fix from $1,600 2026-02-03
Openlist HIGH 8.8
CVE-2026-25059

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability in multiple file operation h…

Fix: 4.1.10+
Fix from $1,950 2026-02-02
Im Server CRITICAL 9.8
CVE-2025-66480

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re…

Fix: 1.4.3+
Fix from $2,300 2026-02-02
Websphere Application Server HIGH 7.6
CVE-2025-14914

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal se…

Fix: after 26.0.0.1
Fix from $1,950 2026-02-02
Unclassified HIGH 8.6
CVE-2026-1186

EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Leg…

Mitigation only
Fix from $1,950 2026-02-02
Unclassified MEDIUM 6.5
CVE-2022-50950

Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attack…

Mitigation only
Fix from $1,600 2026-02-01
Unclassified MEDIUM 6.5
CVE-2021-47921

Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipulate application path requests …

Mitigation only
Fix from $1,600 2026-02-01
Unclassified CRITICAL 9.3
CVE-2026-25069

SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauth…

Mitigation only
Fix from $2,300 2026-02-01
Opencti HIGH 7.5
CVE-2020-37041

OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary files from th…

No fix yet
Fix from $1,950 2026-01-30
Unclassified HIGH 7.5
CVE-2020-37034

HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and fil…

No fix yet
Fix from $1,950 2026-01-30
Backstage MEDIUM 6.5
CVE-2026-25152

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDo…

Fix: 1.13.11 / 1.14.1+
Fix from $1,600 2026-01-30
Crafty Controller HIGH 8.8
CVE-2026-0963

An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to p…

Mitigation only
Fix from $1,950 2026-01-30
Crafty Controller HIGH 8.8
CVE-2026-0805

An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform f…

Fix: 4.8.0+
Fix from $1,950 2026-01-30
Runtipi HIGH 8.8
CVE-2026-25116

Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability …

Fix: 4.7.2+
Fix from $1,950 2026-01-29
Malcontent MEDIUM 5.0
CVE-2026-24846

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8.0 and prior to version 1.20.…

Fix: 1.20.3+
Fix from $1,600 2026-01-29
Umbraco Forms MEDIUM 6.5
CVE-2026-24687

Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enu…

Fix: 16.4.1 / 17.1.1+
Fix from $1,600 2026-01-29
Unclassified HIGH 7.5
CVE-2020-37015

The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access se…

No fix yet
Fix from $1,950 2026-01-29
Open Security Issue Management HIGH 7.5
CVE-2026-1616

The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack…

Fix: 2025.9.0+
Fix from $1,950 2026-01-29
Erugo HIGH 8.8
CVE-2026-24897

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files…

Fix: after 0.2.14
Fix from $1,950 2026-01-28
Dcs 700l Firmware MEDIUM 5.5
CVE-2026-1532

A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the compon…

Fix: after 1.03.09
Fix from $1,600 2026-01-28
66biolinks MEDIUM 6.5
CVE-2025-69601

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are aut…

No fix yet
Fix from $1,600 2026-01-28
Unclassified HIGH 8.4
CVE-2020-36970

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin…

No fix yet
Fix from $1,950 2026-01-28