Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2026-44024 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allo… Fluentd 1.19.3+ Fix from $2,3002026-07-08 HIGH 8.6 CVE-2026-58192 Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage… Patch available Fix from $1,9502026-07-08 MEDIUM 5.9 CVE-2026-54590 AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame… Patch available Fix from $1,6002026-07-08 HIGH 8.1 CVE-2026-54591 AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame… Patch available Fix from $1,9502026-07-08 MEDIUM 6.1 CVE-2026-59946 Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resol… Patch available Fix from $1,6002026-07-08 HIGH 7.0 CVE-2026-59948 Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other t… Patch available Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-59820 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did n… Litellm 1.83.7+ Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-55760 Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass user-controlled input to Handle… Patch available Fix from $1,9502026-07-08 MEDIUM 5.9 CVE-2026-59924 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths with… Mistune 3.3.0+ Fix from $1,6002026-07-08 HIGH 8.8 CVE-2026-53951 Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_setti… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-55668 File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in s… Patch available Fix from $1,6002026-07-08 HIGH 7.7 CVE-2026-55874 SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header us… Patch available Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-56273 Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath p… Mitigation only Fix from $1,6002026-07-08 HIGH 7.8 CVE-2026-22927 Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. Workspace One Tunnel 26.03+ Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-14500 The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to… No fix yet Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-14244 The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' pa… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.1 CVE-2026-14487 The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDi… Mitigation only Fix from $2,3002026-07-08 HIGH 7.2 CVE-2026-55631 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an… Patch available Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-53481 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug… Data Domain Operating System 7.13.1.80 / 8.3.1.40+ Fix from $2,3002026-07-07 HIGH 8.8 CVE-2026-42200 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initializatio… Patch available Fix from $1,9502026-07-07 CRITICAL 9.6 CVE-2026-57571 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 HIGH 7.7 CVE-2026-14468 HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce th… Mitigation only Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-9181 Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could e… Arcgis Server after 12.0 Fix from $1,9502026-07-06 MEDIUM 5.0 CVE-2026-59152 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a serve… Mitigation only Fix from $1,6002026-07-06 HIGH 7.1 CVE-2026-59194 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm p… Pnpm 10.34.4 / 11.7.0+ Fix from $1,9502026-07-06 HIGH 8.2 CVE-2026-59195 pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those na… Pnpm 10.34.4 / 11.8.0+ Fix from $1,9502026-07-06 HIGH 7.1 CVE-2026-59196 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Tra… Pnpm 10.34.4 / 11.7.0+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-58203 pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files i… Pydantic Settings 2.14.2+ Fix from $1,6002026-07-06 MEDIUM 6.0 CVE-2026-7185 A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite.… Mitigation only Fix from $1,6002026-07-06 HIGH 8.1 CVE-2026-49297 Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket … Apache Airflow Providers Google 22.2.1+ Fix from $1,9502026-07-06