Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.0
CVE-2026-16955

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an externa…

No fix yet
Fix from $1,600 2026-08-08
Unclassified CRITICAL 9.2
CVE-2026-47243

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.6
CVE-2026-50540

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47659

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47661

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-71557

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before be…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.9
CVE-2026-62996

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.9
CVE-2026-62992

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the …

No fix yet
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-19264

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload di…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-66914

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download file…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.2
CVE-2026-66491

Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.1
CVE-2026-66492

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action le…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.4
CVE-2026-66493

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move ac…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.8
CVE-2026-16263

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-contr…

No fix yet
Fix from $1,950 2026-08-07
Application Insights Profiler HIGH 8.8
CVE-2026-49163

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-71476

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache ex…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.9
CVE-2026-64677

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requeste…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-64653

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-61632

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vul…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19054

A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/re…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-18427

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent dire…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-53976

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unau…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-28146

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19038

A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file s…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.3
CVE-2026-18991

A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.9
CVE-2026-71313

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-18959

A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopac…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.6
CVE-2026-71309

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve …

No fix yet
Fix from $1,950 2026-08-05
Aws Transform Mcp Server HIGH 8.8
CVE-2026-18953

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 m…

Fix: 0.1.5+
Fix from $1,950 2026-08-05
Enterprise Server CRITICAL 9.1
CVE-2026-17556

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire…

No fix yet
Fix from $2,300 2026-08-05