Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.1 CVE-2026-59510 AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.g… Patch available Fix from $1,9502026-07-05 HIGH 7.3 CVE-2026-14635 A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects… Patch available Fix from $1,9502026-07-04 MEDIUM 5.4 CVE-2026-14636 A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the functio… Patch available Fix from $1,6002026-07-04 MEDIUM 5.3 CVE-2026-14628 A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base… Mitigation only Fix from $1,6002026-07-04 MEDIUM 5.3 CVE-2026-28705 Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially craf… Patch available Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-47896 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-47897 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.1 CVE-2026-9725 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl… Mitigation only Fix from $2,3002026-07-03 HIGH 7.5 CVE-2026-14352 The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter … Mitigation only Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-14327 The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter pa… Mitigation only Fix from $1,9502026-07-03 HIGH 7.2 CVE-2026-13054 A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on… Fireware 12.12.1 / 2026.2.1+ Fix from $1,9502026-07-03 HIGH 7.7 CVE-2026-58460 react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside th… Patch available Fix from $1,9502026-07-02 CRITICAL 9.4 CVE-2026-52830 fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se… No fix yet Fix from $2,3002026-07-02 HIGH 7.5 CVE-2026-58467 Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f… Mitigation only Fix from $1,9502026-07-02 HIGH 8.1 CVE-2026-7311 The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… Mitigation only Fix from $1,9502026-07-02 HIGH 8.6 CVE-2026-55117 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the ho… Unifi Access 4.2.29+ Fix from $1,9502026-07-02 HIGH 8.7 CVE-2026-54406 A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi… Unifi Network Application 10.4.57+ Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-55111 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files o… Protect Floodlight Firmware 1.13.6+ Fix from $1,9502026-07-02 HIGH 8.6 CVE-2026-54403 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authent… Unifi Os Server after 5.1.15 Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-13369 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and inclu… Mitigation only Fix from $1,9502026-07-02 MEDIUM 6.5 CVE-2026-9145 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() functio… Mitigation only Fix from $1,6002026-07-02 HIGH 7.5 CVE-2026-13251 The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This mak… Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.4 CVE-2026-14439 A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence … Mitigation only Fix from $2,3002026-07-01 MEDIUM 6.5 CVE-2026-58451 Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from th… Patch available Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-49119 Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers… Gradio 6.16.0+ Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-20191 A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  … Mitigation only Fix from $1,9502026-07-01 HIGH 8.2 CVE-2026-53906 MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the … Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 HIGH 8.3 CVE-2026-56233 Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to b… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-50003 A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, us… Mitigation only Fix from $2,3002026-06-30 HIGH 8.2 CVE-2026-52868 An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment,… Mitigation only Fix from $1,9502026-06-30