Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.4 CVE-2026-29509 Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python … Mitigation only Fix from $1,6002026-06-26 HIGH 8.1 CVE-2026-56876 extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative… Extract Zip after 2.0.1 Fix from $1,9502026-06-26 MEDIUM 5.5 CVE-2026-54557 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from … Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-55677 Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes… Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-57321 Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions. No fix yet Fix from $1,9502026-06-26 MEDIUM 5.8 CVE-2026-56066 Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.4 CVE-2026-13426 The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API rou… Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.1 CVE-2025-55017 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from … Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.1 CVE-2025-64152 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from … Mitigation only Fix from $2,3002026-06-26 HIGH 7.5 CVE-2026-57872 An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-40084 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report fo… Cacti 1.2.31+ Fix from $1,6002026-06-25 CRITICAL 9.1 CVE-2026-56445 The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizatio… Mitigation only Fix from $2,3002026-06-25 HIGH 8.2 CVE-2026-55667 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,9502026-06-25 CRITICAL 10.0 CVE-2026-54917 SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceber… Seaweedfs 4.30+ Fix from $2,3002026-06-25 MEDIUM 6.8 CVE-2026-54093 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-54094 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.8 CVE-2026-54250 K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability … Mitigation only Fix from $1,6002026-06-25 HIGH 7.8 CVE-2026-53925 Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets … Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-50548 Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra… Cursor 3.0+ Fix from $2,3002026-06-25 HIGH 7.1 CVE-2026-55700 pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version… Pnpm 11.5.3+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-55699 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malic… Pnpm 10.34.2 / 11.5.3+ Fix from $1,6002026-06-25 HIGH 7.3 CVE-2026-50015 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file p… Pnpm 10.34.0 / 11.4.0+ Fix from $1,9502026-06-25 MEDIUM 5.5 CVE-2026-55439 Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated ad… Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-55092 Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the ar… Trivy 0.71.1+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-45233 HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by sup… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-48944 The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::co… K2 after 2.26 Fix from $1,6002026-06-25 HIGH 7.7 CVE-2026-56054 Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-56122 Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sendi… Mitigation only Fix from $1,9502026-06-25 HIGH 7.2 CVE-2026-49506 Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') … Wyse Management Suite 5.5+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-9153 Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express… Sed Mitigation only Fix from $1,6002026-06-25