Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified CRITICAL 9.8
CVE-2026-1056EPSS 12%

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_di…

Mitigation only
Fix from $2,300 2026-01-28
Tar HIGH 8.2
CVE-2026-24842

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path res…

Fix: 7.5.7+
Fix from $1,950 2026-01-28
Convertx HIGH 8.1
CVE-2026-24741

ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to c…

Fix: 0.17.0+
Fix from $1,950 2026-01-27
Ragflow CRITICAL 9.8
CVE-2026-24770

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a …

Fix: after 0.23.1
Fix from $2,300 2026-01-27
Unclassified HIGH 7.5
CVE-2026-23593

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view …

Mitigation only
Fix from $1,950 2026-01-27
Unclassified HIGH 7.5
CVE-2020-36939

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path t…

No fix yet
Fix from $1,950 2026-01-27
Unclassified MEDIUM 6.9
CVE-2026-24801

Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source modules). This vulnerability is …

Patch available
Fix from $1,600 2026-01-27
Hustoj CRITICAL 9.8
CVE-2026-24479EPSS 8%

HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduo…

Fix: 26.01.24+
Fix from $2,300 2026-01-27
Python Multipart HIGH 7.5
CVE-2026-24486

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default co…

Fix: 0.0.22+
Fix from $1,950 2026-01-27
Anythingllm HIGH 7.2
CVE-2026-24478

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, …

Fix: 1.10.0+
Fix from $1,950 2026-01-27
Bentoml MEDIUM 6.5
CVE-2026-24123

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's `bentof…

Fix: 1.4.34+
Fix from $1,600 2026-01-26
Pnpm MEDIUM 6.5
CVE-2026-23888

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files…

Fix: 10.28.1+
Fix from $1,600 2026-01-26
Pnpm MEDIUM 6.5
CVE-2026-23889

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write f…

Fix: 10.28.1+
Fix from $1,600 2026-01-26
Pnpm MEDIUM 6.5
CVE-2026-24056

pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads the…

Fix: 10.28.2+
Fix from $1,600 2026-01-26
Pnpm MEDIUM 5.5
CVE-2026-24131

pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validatin…

Fix: 10.28.2+
Fix from $1,600 2026-01-26
Unclassified HIGH 7.5
CVE-2026-24469

C++ HTTP Server is an HTTP/1.1 server built to handle client connections and serve HTTP requests. Versions 1.0 and below are vulnerable to Path Trave…

Mitigation only
Fix from $1,950 2026-01-24
7 Zip HIGH 7.8
CVE-2025-11002

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2026-01-23
Container HIGH 7.8
CVE-2026-20613

The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an ar…

Fix: 0.8.0 / 0.21.0+
Fix from $1,950 2026-01-23
Unclassified MEDIUM 5.8
CVE-2026-24137

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/c…

Patch available
Fix from $1,600 2026-01-23
Azure Logic Apps CRITICAL 9.8
CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

Mitigation only
Fix from $2,300 2026-01-22
Incus HIGH 8.7
CVE-2026-23954

Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom …

Fix: 6.21.0+
Fix from $1,950 2026-01-22
Unclassified HIGH 8.8
CVE-2025-66428

An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.6
CVE-2025-69097

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.T…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified MEDIUM 6.5
CVE-2025-69055

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Tr…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified HIGH 8.6
CVE-2025-68912

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2025-68907

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 hostmev2 allows Path Traversal.…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.6
CVE-2025-68901

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This is…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2025-68902

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This is…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.6
CVE-2025-67963

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ovatheme Movie Booking movie-booking allows Path Trav…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.7
CVE-2023-7335

EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unau…

Mitigation only
Fix from $1,950 2026-01-22