Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-53571 Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny ca… Vite 0.1.24 / 6.4.3+ Fix from $1,9502026-06-22 MEDIUM 6.1 CVE-2026-12479 A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model savi… Mitigation only Fix from $1,6002026-06-22 HIGH 8.3 CVE-2026-56448 A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticate… Patch available Fix from $1,9502026-06-22 HIGH 7.7 CVE-2026-42129 A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive back… Loki Datasource Mitigation only Fix from $1,9502026-06-22 MEDIUM 6.3 CVE-2026-12821 A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/do… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.5 CVE-2026-56394 Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not vali… Patch available Fix from $1,6002026-06-21 HIGH 7.5 CVE-2026-11911 The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile f… Mitigation only Fix from $1,9502026-06-20 HIGH 8.1 CVE-2026-9843 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… Mitigation only Fix from $1,9502026-06-20 MEDIUM 6.5 CVE-2026-48129 Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes … Mitigation only Fix from $1,6002026-06-19 MEDIUM 5.3 CVE-2026-49342 YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path b… Patch available Fix from $1,6002026-06-19 HIGH 7.1 CVE-2026-49339 gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a7d… Patch available Fix from $1,9502026-06-19 HIGH 8.1 CVE-2026-49340 gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdateP… Mitigation only Fix from $1,9502026-06-19 HIGH 7.6 CVE-2026-49290 Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-… Patch available Fix from $1,9502026-06-19 MEDIUM 5.3 CVE-2026-56138 AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2… Patch available Fix from $1,6002026-06-19 CRITICAL 9.1 CVE-2026-8713 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete… Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-54414 FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitr… No fix yet Fix from $2,3002026-06-19 HIGH 8.8 CVE-2026-56078 PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Atta… Mitigation only Fix from $1,9502026-06-18 HIGH 7.7 CVE-2026-54017 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy … Open Webui 0.9.6+ Fix from $1,9502026-06-18 HIGH 8.7 CVE-2026-48716 nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path usi… Mitigation only Fix from $1,9502026-06-18 HIGH 8.6 CVE-2026-54223 UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s serv… Mitigation only Fix from $1,9502026-06-18 HIGH 7.1 CVE-2026-8811 SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to crea… Mitigation only Fix from $1,9502026-06-18 CRITICAL 9.3 CVE-2026-48768 TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses uns… Mitigation only Fix from $2,3002026-06-18 MEDIUM 6.5 CVE-2026-12568 The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malic… Patch available Fix from $1,6002026-06-17 MEDIUM 5.3 CVE-2026-12565 The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavio… Patch available Fix from $1,6002026-06-17 MEDIUM 6.3 CVE-2026-48820 CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and… Mitigation only Fix from $1,6002026-06-17 MEDIUM 6.5 CVE-2026-49133 Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary fil… Patch available Fix from $1,6002026-06-17 MEDIUM 6.8 CVE-2026-55201 Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compro… Patch available Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-53872 picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by… Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-20181 A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating syst… Identity Services Engine 3.3.0+ Fix from $2,3002026-06-17 HIGH 7.7 CVE-2026-54193 Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions. Mitigation only Fix from $1,9502026-06-17