Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2026-52716 Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. Mitigation only Fix from $1,6002026-06-17 HIGH 8.6 CVE-2025-69128 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affe… Mitigation only Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-9690 Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-50203 A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv… Apache Airflow Providers Sftp 5.8.1+ Fix from $2,3002026-06-17 CRITICAL 10.0 CVE-2026-48055 Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vul… Mitigation only Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2026-47277 Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-sto… Mitigation only Fix from $1,6002026-06-17 MEDIUM 6.5 CVE-2026-40724 CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. Mitigation only Fix from $1,6002026-06-17 HIGH 8.6 CVE-2026-27400 Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-22334 Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.8 CVE-2026-10094 A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allo… Mitigation only Fix from $2,3002026-06-17 HIGH 8.6 CVE-2025-69139 Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.5 CVE-2025-69131 Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.7 CVE-2025-60223 Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.5 CVE-2024-32729 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows … Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-48776 LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versio… Langgraph Sdk 0.3.15+ Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-48777 FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path … Mitigation only Fix from $2,3002026-06-16 HIGH 8.1 CVE-2026-8442 The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing… Mitigation only Fix from $1,9502026-06-16 CRITICAL 9.9 CVE-2026-49766 Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. Mitigation only Fix from $2,3002026-06-15 HIGH 7.5 CVE-2026-49061 Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.7 CVE-2026-40779 Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 8.6 CVE-2026-40769 Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code Field <= 1.0.6 version… Mitigation only Fix from $1,9502026-06-15 HIGH 7.7 CVE-2026-40727 Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions. Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.8 CVE-2026-39468 Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions. Mitigation only Fix from $1,6002026-06-15 HIGH 7.5 CVE-2026-50877 An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-50869 An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-45390 In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired be… No fix yet Fix from $2,3002026-06-15 MEDIUM 6.5 CVE-2026-20262 KEVEPSS 28% A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a fi… Catalyst Sd Wan Manager 20.9.9.2 / 20.12.7.2+ Fix from $1,6002026-06-15 HIGH 7.5 CVE-2016-20081 WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary file… No fix yet Fix from $1,9502026-06-15 HIGH 7.5 CVE-2016-20076 WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitiv… No fix yet Fix from $1,9502026-06-15 HIGH 7.3 CVE-2026-12198 A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the c… Mitigation only Fix from $1,9502026-06-15