Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2026-65689 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that all… Standalone Report Designer 14.1.12+ Fix from $2,3002026-07-23 HIGH 8.8 CVE-2026-65690 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that all… Standalone Report Designer 14.1.12+ Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-65687 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows… Standalone Report Designer 14.1.12+ Fix from $2,3002026-07-23 MEDIUM 6.5 CVE-2026-65607 SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serv… No fix yet Fix from $1,6002026-07-23 HIGH 7.7 CVE-2026-59542 Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. No fix yet Fix from $1,9502026-07-23 CRITICAL 10.0 CVE-2026-59555 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. No fix yet Fix from $2,3002026-07-23 HIGH 7.1 CVE-2026-57696 Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-57716 Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-65754 Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the s… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-64872 Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directo… No fix yet Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-65431 Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation… Mitigation only Fix from $2,3002026-07-23 MEDIUM 6.2 CVE-2026-65712 Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-65713 Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-16078 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-15074 @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This … Fastify Static 10.1.1+ Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-16653 A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of… No fix yet Fix from $1,6002026-07-23 HIGH 7.8 CVE-2026-14985 The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to… No fix yet Fix from $1,9502026-07-22 HIGH 8.1 CVE-2026-13186 In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploite… Telerik Ui For Asp.net Ajax 2026.2.708+ Fix from $1,9502026-07-22 MEDIUM 5.3 CVE-2026-65600 Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathReg… Traefik 2.11.52 / 3.6.23+ Fix from $1,6002026-07-22 MEDIUM 6.6 CVE-2026-44192 A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to ma… No fix yet Fix from $1,6002026-07-22 HIGH 8.4 CVE-2026-56844 A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain roo… No fix yet Fix from $1,9502026-07-22 CRITICAL 9.1 CVE-2026-47731 The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to … No fix yet Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-30633 Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools. No fix yet Fix from $1,9502026-07-21 HIGH 7.8 CVE-2026-50757 Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-… No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-30632 Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool. No fix yet Fix from $1,9502026-07-21 HIGH 7.2 CVE-2026-63454 An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary fi… Arubaos Cx after 10.18.0001 Fix from $1,9502026-07-21 MEDIUM 6.9 CVE-2026-47425 Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_c… No fix yet Fix from $1,6002026-07-21 HIGH 7.1 CVE-2026-47397 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled c… No fix yet Fix from $1,9502026-07-21 HIGH 8.7 CVE-2026-15724 In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal … No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-15789 A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The cli… Buildkit 0.31.2+ Fix from $1,9502026-07-21