Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-15791 A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used … Buildkit 0.31.2+ Fix from $1,9502026-07-21 HIGH 8.4 CVE-2026-64824 Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to ar… Mitigation only Fix from $1,9502026-07-21 CRITICAL 9.3 CVE-2026-64825 Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any dir… No fix yet Fix from $2,3002026-07-21 HIGH 8.7 CVE-2026-47394 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original adviso… No fix yet Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-47121 Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents con… Sparkle 2.9.2+ Fix from $1,6002026-07-21 MEDIUM 5.9 CVE-2026-13693 The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a no… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.5 CVE-2026-47144 Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-con… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-56452 Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The impleme… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-56623 Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git s… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-60027 Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder … No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-58484 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manife… Network Ai 5.12.2+ Fix from $1,9502026-07-20 MEDIUM 6.1 CVE-2026-58413 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup… Network Ai 5.12.2+ Fix from $1,6002026-07-20 MEDIUM 5.5 CVE-2026-58414 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using … Network Ai 5.12.2+ Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-58481 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured s… Network Ai 5.12.2+ Fix from $1,6002026-07-20 HIGH 7.1 CVE-2026-46555 WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1… Whatsapp Mcp Server No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-32820 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 8.2 CVE-2026-45711 Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads … Mailpit 1.30.0+ Fix from $1,9502026-07-20 HIGH 7.7 CVE-2026-54910 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/sub… No fix yet Fix from $1,9502026-07-20 HIGH 7.8 CVE-2026-52349 Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary … No fix yet Fix from $1,9502026-07-20 CRITICAL 9.0 CVE-2026-12701 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but… No fix yet Fix from $2,3002026-07-20 HIGH 7.7 CVE-2026-63739 SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or O… Surrealdb 3.1.5+ Fix from $1,9502026-07-20 MEDIUM 6.5 CVE-2026-12898 The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.3 CVE-2026-16219 A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.ph… No fix yet Fix from $1,6002026-07-19 CRITICAL 10.0 CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the confi… Fastify\/http Proxy 11.6.0+ Fix from $2,3002026-07-18 HIGH 8.8 CVE-2026-47871 VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to … Mitigation only Fix from $1,9502026-07-18 MEDIUM 5.3 CVE-2026-48049 @hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured… No fix yet Fix from $1,6002026-07-17 CRITICAL 9.9 CVE-2026-8859 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat… Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 8.1 CVE-2026-7872 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication… Langflow 1.10.1+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns… Langflow 1.10.1+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-50163 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relat… No fix yet Fix from $1,9502026-07-17