Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.5 CVE-2026-7521 Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin… Mattermost Server 10.11.21 / 11.6.6+ Fix from $1,6002026-07-28 HIGH 7.2 CVE-2026-16585 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to in… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-14490 The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-17524 Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extractio… No fix yet Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-64731 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be a… macOS 15.7.8 / 26.6+ Fix from $2,3002026-07-27 CRITICAL 9.3 CVE-2026-64740 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10… Ipados 14.8.8 / 15.7.8+ Fix from $2,3002026-07-27 HIGH 8.2 CVE-2026-43772 A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-43749 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS So… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-43723 A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS … Ipados 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 8.8 CVE-2026-65921 A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build arti… Artifactory 7.111.18 / 7.117.25+ Fix from $1,9502026-07-27 CRITICAL 9.1 CVE-2026-45623 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.… Postcss 8.5.12+ Fix from $2,3002026-07-27 HIGH 8.6 CVE-2026-66397 phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attacker… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-66050 NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the… No fix yet Fix from $1,9502026-07-27 MEDIUM 6.8 CVE-2026-65436 Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. No fix yet Fix from $1,6002026-07-27 HIGH 8.3 CVE-2026-65878 Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a… No fix yet Fix from $1,9502026-07-27 MEDIUM 5.3 CVE-2026-17514 A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.9 CVE-2026-65765 Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download action… No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-14955 The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7… No fix yet Fix from $1,6002026-07-25 MEDIUM 5.3 CVE-2026-66004 BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitr… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-66007 Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadat… Datasets No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-16767 A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the componen… No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-65694 Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to r… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.3 CVE-2026-47669 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`… No fix yet Fix from $2,3002026-07-23 HIGH 7.5 CVE-2026-65919 Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoint… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-65700 h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-65701 SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una… No fix yet Fix from $2,3002026-07-23 HIGH 8.6 CVE-2026-65702 Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated re… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-65698 Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrar… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.8 CVE-2026-65695 Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filen… No fix yet Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-65688 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allow… Standalone Report Designer 14.1.12+ Fix from $2,3002026-07-23