Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.1 CVE-2026-52886 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::w… Fix unknown Fix from $4,0002026-08-17 HIGH 8.1 CVE-2026-57233 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-63667 ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzi… Fix unknown Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-50776 Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute … Fix unknown Fix from $4,9002026-08-17 HIGH 8.4 CVE-2026-46345 compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle … Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-73646 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18,… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.1 CVE-2026-73851 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description co… Fix unknown Fix from $4,0002026-08-17 HIGH 8.1 CVE-2026-19693 extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an ar… Fix unknown Fix from $4,9002026-08-17 HIGH 7.2 CVE-2026-16137 In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uplo… Fix unknown Fix from $4,9002026-08-17 HIGH 7.2 CVE-2026-16139 In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation i… Fix unknown Fix from $4,9002026-08-17 HIGH 8.7 CVE-2026-74798 SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on t… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.1 CVE-2026-19725 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before usin… Fix unknown Fix from $5,7502026-08-16 MEDIUM 6.5 CVE-2026-15056 The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversa… No fix yet Fix from $4,0002026-08-16 CRITICAL 9.1 CVE-2026-14524 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe… No fix yet Fix from $5,7502026-08-16 CRITICAL 10.0 CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor p… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.1 CVE-2026-18855 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields … No fix yet Fix from $5,7502026-08-15 CRITICAL 9.1 CVE-2026-14484 The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat… No fix yet Fix from $5,7502026-08-15 MEDIUM 5.4 CVE-2026-18178 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-18554 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pa… No fix yet Fix from $4,9002026-08-14 HIGH 8.2 CVE-2026-17081 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricte… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-17173 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file… No fix yet Fix from $4,0002026-08-14 CRITICAL 9.3 CVE-2026-17181 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. No fix yet Fix from $5,7502026-08-14 HIGH 7.5 CVE-2026-16915 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. No fix yet Fix from $4,9002026-08-14 MEDIUM 6.8 CVE-2026-57471 Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.9 CVE-2026-57472 Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19880 Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, … No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-19827 A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19828 A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the compo… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-72814 The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the… No fix yet Fix from $4,0002026-08-14 HIGH 7.3 CVE-2026-19762 A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the… No fix yet Fix from $4,9002026-08-14