Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Langflow MEDIUM 6.5
CVE-2026-7658

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow MEDIUM 5.4
CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs becaus…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow HIGH 7.7
CVE-2026-8183

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7646

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.3
CVE-2026-9195

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.1
CVE-2026-15979

The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in v…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.0
CVE-2026-71279

Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT message (topic zigbee2mqtt/bridge/…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-71268

OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes t…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.2
CVE-2026-71269

Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-red/runtime/lib/storage/local…

No fix yet
Fix from $1,950 2026-08-05
Mojarra HIGH 7.5
CVE-2026-46581

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a…

Fix: after 4.1.13
Fix from $1,950 2026-08-05
Theia HIGH 7.5
CVE-2026-61891

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Theia HIGH 8.8
CVE-2026-60009

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Theia HIGH 7.5
CVE-2026-12609

In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71209

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requ…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71215

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, reso…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-55747

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonica…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 10.0
CVE-2026-16940

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete…

No fix yet
Fix from $2,300 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-18853

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the componen…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.5
CVE-2026-70592

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the fil…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.6
CVE-2026-70593

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside …

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-47682

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write acce…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.4
CVE-2026-47764

pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through…

No fix yet
Fix from $1,950 2026-08-04
Triton Inference Server HIGH 7.1
CVE-2026-47487

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to,…

Fix unknown
Fix from $1,950 2026-08-04
Dynamo HIGH 7.5
CVE-2026-47612

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a re…

Fix: after 1.0.0
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.0
CVE-2026-58072

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-69110

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files wit…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67200

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesy…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14194

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMAN…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.2
CVE-2026-14818

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-56845

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By includin…

No fix yet
Fix from $1,950 2026-08-04