Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2026-9154 Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content t… Sed Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-39899 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter… Cacti 1.2.31+ Fix from $1,6002026-06-24 CRITICAL 9.8 CVE-2026-39938 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo… Cacti 1.2.31+ Fix from $2,3002026-06-24 MEDIUM 6.5 CVE-2026-9774 ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary f… Unizon 2.7.264+ Fix from $1,6002026-06-24 MEDIUM 6.5 CVE-2026-9775 ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files… Unizon 2.7.264+ Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-9776 ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to di… Unizon 2.7.264+ Fix from $1,9502026-06-24 HIGH 7.2 CVE-2026-9777 ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… Unizon 2.7.264+ Fix from $1,9502026-06-24 HIGH 7.2 CVE-2026-9778 ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Unizon 2.7.264+ Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-54066 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding"… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.1 CVE-2026-53766 Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContex… Chrome Devtools Mcp 1.1.0+ Fix from $1,6002026-06-24 CRITICAL 9.0 CVE-2026-52811 Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload tar… Patch available Fix from $2,3002026-06-24 HIGH 8.5 CVE-2026-52797 Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git … Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.5 CVE-2026-31978 motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 ar… Mitigation only Fix from $1,6002026-06-24 HIGH 8.8 CVE-2026-49247 Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization head… Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-44017 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the E… Docling 2.91.0+ Fix from $1,9502026-06-24 MEDIUM 5.5 CVE-2026-44022 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91… Docling 2.91.0+ Fix from $1,6002026-06-24 HIGH 7.7 CVE-2026-55488 motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Version… Mitigation only Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-57296 Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exw… No fix yet Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-47385 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create permission can attach a SQLite … Mitigation only Fix from $1,6002026-06-23 CRITICAL 10.0 CVE-2026-48020 Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPre… Traefik 2.11.48 / 3.6.19+ Fix from $2,3002026-06-23 HIGH 7.5 CVE-2026-52844 Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outsid… Caddy 2.11.4+ Fix from $1,9502026-06-23 MEDIUM 5.5 CVE-2026-49406 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module re… Deno 2.7.12+ Fix from $1,6002026-06-23 HIGH 7.7 CVE-2026-49465 n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify … N8n 1.123.48 / 2.21.8+ Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-42867 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle… Langflow 1.9.0+ Fix from $1,6002026-06-23 HIGH 7.8 CVE-2026-11940 tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deepe… Patch available Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-56258 Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to wri… Crawl4ai 0.8.8+ Fix from $1,9502026-06-23 MEDIUM 5.5 CVE-2026-55443 LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths… Langchain 1.3.9+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-54293 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan… Nltk 3.10.0+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-53779 WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the conf… Patch available Fix from $1,9502026-06-22 MEDIUM 5.9 CVE-2026-54286 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) … Mitigation only Fix from $1,6002026-06-22