Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Kyuubi CRITICAL 9.8
CVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …

Fix: 1.12.0+
Fix from $2,300 2026-07-30
Calico HIGH 7.5
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re…

Fix: 3.21.7 / 3.22.4+
Fix from $1,950 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-15435

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
App Connect Enterprise HIGH 7.5
CVE-2026-14519

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a …

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $1,950 2026-07-30
Vcenter Server CRITICAL 9.8
CVE-2026-59310 KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-16531

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows…

No fix yet
Fix from $1,600 2026-07-30
Data Master MEDIUM 6.5
CVE-2026-67247

A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not su…

Fix: 5.1.4.rjv2+
Fix from $1,600 2026-07-30
Data Master HIGH 8.1
CVE-2026-67245

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is no…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master MEDIUM 6.5
CVE-2026-67246

A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is …

Fix: 5.1.4.rjv2+
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-5491

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-5492

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-5487

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-5489

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,600 2026-07-29
Unclassified CRITICAL 10.0
CVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-13723

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by expl…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 5.9
CVE-2026-50558

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in p…

No fix yet
Fix from $1,600 2026-07-29
Gridbox HIGH 7.5
CVE-2026-65886

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view …

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Gridbox HIGH 7.5
CVE-2026-65889

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.9
CVE-2026-44943

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.6
CVE-2026-11974

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two A…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-66063

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler s…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-54659

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.6
CVE-2026-54650

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.P…

No fix yet
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 7.5
CVE-2026-55389

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.62.0+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-55390

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_gen…

No fix yet
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-15280

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-28
Aspera CRITICAL 9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Fix: after 1.0.19
Fix from $2,300 2026-07-28
Bridge HIGH 7.8
CVE-2026-48374

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary fi…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-67185

TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequenc…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.1
CVE-2026-54545

wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once …

No fix yet
Fix from $1,950 2026-07-28