Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2026-15749 A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/… Mitigation only Fix from $1,6002026-07-14 HIGH 8.6 CVE-2026-48350 Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary… Animate 23.0.16 / 24.0.14+ Fix from $1,9502026-07-14 HIGH 8.6 CVE-2026-48310 Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could le… Experience Manager after 2020.5.0 Fix from $1,9502026-07-14 MEDIUM 5.9 CVE-2026-47429 Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly fo… Vitest 3.2.5 / 4.1.0+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-45496 Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a secu… Visual Studio Code 1.128.1+ Fix from $1,6002026-07-14 MEDIUM 5.4 CVE-2026-9108 A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The soft… Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-59839 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0… Fortiproxy 1.7.3 / 7.4.10+ Fix from $1,6002026-07-14 HIGH 7.7 CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method buil… Patch available Fix from $1,9502026-07-14 HIGH 7.2 CVE-2026-11917 A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-11944 openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that a… Opensis Mitigation only Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-60114 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore… Sustainable Irrigation Platform after 5.2.16 Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-14903 Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. Xtraction 2026.2.1+ Fix from $1,6002026-07-14 CRITICAL 9.1 CVE-2026-15265 A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende… Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-49488 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenM… Openmeetings 9.1.0+ Fix from $1,6002026-07-14 CRITICAL 9.0 CVE-2026-57898 In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauth… Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-12482 A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` valid… Keras No fix yet Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15626 A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_… Mitigation only Fix from $1,6002026-07-14 HIGH 8.8 CVE-2026-57856 Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controll… Patch available Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-49970 Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded fi… Patch available Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-26396 OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The … Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.3 CVE-2026-61505 Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain … Mitigation only Fix from $1,6002026-07-13 HIGH 7.5 CVE-2026-57815 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Formina… Mitigation only Fix from $1,9502026-07-13 HIGH 8.6 CVE-2026-57709 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-w… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.9 CVE-2026-57401 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traver… Mitigation only Fix from $2,3002026-07-13 HIGH 8.6 CVE-2026-57389 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traver… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.2 CVE-2026-13014 A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrari… Mitigation only Fix from $2,3002026-07-13 MEDIUM 5.3 CVE-2026-15527 A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/s… Mitigation only Fix from $1,6002026-07-13 MEDIUM 5.3 CVE-2026-15522 A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build… Patch available Fix from $1,6002026-07-13 MEDIUM 5.3 CVE-2026-15521 A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the com… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.1 CVE-2026-56260 Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path param… Crawl4ai 0.8.7+ Fix from $2,3002026-07-12