Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.4
CVE-2026-18645

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the co…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18646

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component A…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18648

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFile…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18644

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the compo…

No fix yet
Fix from $1,600 2026-08-03
Postcss MEDIUM 5.3
CVE-2026-69153

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19,…

Fix: 8.5.23+
Fix from $1,600 2026-08-03
Jena Fuseki HIGH 7.5
CVE-2026-61372

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F…

Fix: 6.2.0+
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69095

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69089

Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Tool…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.7
CVE-2026-69086

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to constr…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.1
CVE-2026-9856

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue r…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-9335

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalL…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.5
CVE-2026-13339

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_c…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-18352

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' p…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.8
CVE-2026-67309

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67295

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.1
CVE-2026-15450

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and …

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.2
CVE-2026-15244

The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inc…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-15932

The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthentica…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.5
CVE-2026-15006

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.2
CVE-2026-54785

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-62999

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 8.7
CVE-2026-53502

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boun…

No fix yet
Fix from $1,950 2026-07-31
Kyuubi HIGH 8.1
CVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-…

Fix: 1.12.0+
Fix from $1,950 2026-07-31
Zeppelin MEDIUM 6.5
CVE-2026-44615

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not…

Fix: 0.12.1+
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-63222

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filena…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-56673

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and …

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-56671

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py jo…

No fix yet
Fix from $1,950 2026-07-31
Tika HIGH 7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker…

Fix: 3.3.2+
Fix from $1,950 2026-07-30
Langflow HIGH 7.5
CVE-2026-12942

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted…

Fix: 1.10.2+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-62663

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, doc…

No fix yet
Fix from $1,950 2026-07-30