Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.5 CVE-2026-73973 Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/log… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-73974 linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses … Fix unknown Fix from $4,0002026-08-18 HIGH 8.4 CVE-2026-52875 Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-52872 Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.4 CVE-2026-47699 Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafte… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-48796 CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to vers… Fix unknown Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-50186 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal s… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-53457 Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command executio… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.8 CVE-2026-47627 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to de… Fix unknown Fix from $5,7502026-08-18 HIGH 7.1 CVE-2026-74038 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrollin… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-74044 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by s… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-68922 MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py u… Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-75914 CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading … Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75859 CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on … Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.8 CVE-2026-63328 Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins wit… Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73181 Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-48798 SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trus… Fix unknown Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-45532 DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is tha… Fix unknown Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-75855 ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, all… Fix unknown Fix from $4,9002026-08-18 HIGH 7.7 CVE-2026-75842 ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users t… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.9 CVE-2026-74907 Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di… Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-15585 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-42162 Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact… Fix unknown Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-67918 Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-75111 Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read ar… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-75482 SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.5 CVE-2026-75104 Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model d… Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.4 CVE-2026-54336 JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user wit… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-40506 OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without… Fix unknown Fix from $4,0002026-08-17 HIGH 7.1 CVE-2026-19589 Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead t… Fix unknown Fix from $4,9002026-08-17