Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-45309 AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame… Asyncssh 2.23.0+ Fix from $1,9502026-07-17 HIGH 8.6 CVE-2026-15343 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updat… No fix yet Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62229 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute ac… Openclaw 2026.5.18+ Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-39359 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.1… Wazuh 4.10.4 / 4.14.5+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-44177 Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user… No fix yet Fix from $1,9502026-07-16 HIGH 8.6 CVE-2026-44023 Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.… Docling Core 2.74.1+ Fix from $1,9502026-07-16 HIGH 7.3 CVE-2024-32386 Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive in… No fix yet Fix from $1,9502026-07-16 HIGH 8.7 CVE-2026-55629 Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req… Patch available Fix from $1,9502026-07-16 MEDIUM 5.9 CVE-2026-53535 Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a … Patch available Fix from $1,6002026-07-16 HIGH 7.1 CVE-2026-46336 Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 unti… Patch available Fix from $1,9502026-07-16 CRITICAL 9.1 CVE-2026-45568 zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an ab… Zrok 2.0.3+ Fix from $2,3002026-07-16 HIGH 7.5 CVE-2026-45576 zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or z… Zrok 2.0.3+ Fix from $1,9502026-07-16 HIGH 7.3 CVE-2026-13103 A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local au… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2025-45870 LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated … No fix yet Fix from $1,6002026-07-16 CRITICAL 9.3 CVE-2026-59864 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`… Patch available Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-59866 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa… Patch available Fix from $2,3002026-07-16 HIGH 7.1 CVE-2026-59867 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs … Patch available Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-53598 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty fron… Patch available Fix from $1,9502026-07-16 HIGH 7.0 CVE-2026-59863 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configurat… Patch available Fix from $1,9502026-07-16 HIGH 7.1 CVE-2026-52890 Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /att… Patch available Fix from $1,9502026-07-15 HIGH 8.5 CVE-2026-45419 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticRes… Patch available Fix from $1,9502026-07-15 HIGH 8.3 CVE-2026-45533 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequence… Patch available Fix from $1,9502026-07-15 MEDIUM 5.4 CVE-2026-26032 The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repa… Ivy 2.6.0+ Fix from $1,6002026-07-15 HIGH 7.5 CVE-2026-12997 The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_file… Mitigation only Fix from $1,9502026-07-15 HIGH 7.2 CVE-2026-20297 In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10… Splunk 9.3.14 / 9.4.13+ Fix from $1,9502026-07-15 MEDIUM 5.5 CVE-2026-20146 A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attac… Identity Services Engine Passive Identity Connector 3.3.0+ Fix from $1,6002026-07-15 MEDIUM 6.8 CVE-2026-62843 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 … Patch available Fix from $1,6002026-07-15 MEDIUM 6.4 CVE-2026-60062 The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secur… Nginx Agent 2.22.2 / 2.46.7+ Fix from $1,6002026-07-15 CRITICAL 9.1 CVE-2026-43637 Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache dire… Patch available Fix from $2,3002026-07-15 HIGH 8.1 CVE-2026-61443 PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containmen… Mitigation only Fix from $1,9502026-07-15