Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2026-11769 We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation… Grafana Operator 5.24.0+ Fix from $1,9502026-06-13 MEDIUM 6.5 CVE-2026-11442 Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive infor… Mitigation only Fix from $1,6002026-06-13 MEDIUM 6.5 CVE-2026-53825 OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators … Openclaw 2026.4.7+ Fix from $1,6002026-06-12 CRITICAL 9.1 CVE-2026-53519 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the da… Mitigation only Fix from $2,3002026-06-12 MEDIUM 5.3 CVE-2026-54394 MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using or… Patch available Fix from $1,6002026-06-12 MEDIUM 6.8 CVE-2026-45775 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-l… Discourse 2026.1.0 / 2026.1.4+ Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-43872 Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Ver… Mitigation only Fix from $1,6002026-06-12 HIGH 7.8 CVE-2026-44171 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $1,9502026-06-12 HIGH 7.6 CVE-2026-6961 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received … Mattermost Server 10.11.17 / 11.5.5+ Fix from $1,9502026-06-12 HIGH 7.1 CVE-2026-3840 A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()… Kedro No fix yet Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-11846 The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated rem… Mitigation only Fix from $1,9502026-06-12 HIGH 8.6 CVE-2026-47368 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data fr… Mitigation only Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-45171 Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6… Idira Privileged Session Manager 14.0.5 / 14.2.5+ Fix from $1,9502026-06-11 MEDIUM 5.5 CVE-2025-24268 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may… macOS 15.4+ Fix from $1,6002026-06-11 HIGH 8.2 CVE-2026-49982 tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that conta… Tmp No fix yet Fix from $1,9502026-06-11 HIGH 8.2 CVE-2026-44705 tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows es… Tmp 0.2.6+ Fix from $1,9502026-06-11 HIGH 8.1 CVE-2026-53777 Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writabl… Patch available Fix from $1,9502026-06-11 HIGH 8.1 CVE-2026-11816 Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py… Keras 3.14.0+ Fix from $1,9502026-06-11 HIGH 8.3 CVE-2026-8464 Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitr… Mitigation only Fix from $1,9502026-06-11 HIGH 7.1 CVE-2026-40987 A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) w… Mitigation only Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-52726 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcel… Mitigation only Fix from $1,9502026-06-10 MEDIUM 5.5 CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect… Imagemagick 6.9.13-48 / 7.1.2-24+ Fix from $1,6002026-06-10 CRITICAL 9.6 CVE-2026-46703 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted … Mitigation only Fix from $2,3002026-06-10 HIGH 8.8 CVE-2026-42305 Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary fil… Patch available Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-0270 A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent… Cortex Xsoar 8.13.0.11+ Fix from $1,9502026-06-10 HIGH 7.7 CVE-2026-50567 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-45569 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validat… Patch available Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-45565 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxy… Mitigation only Fix from $1,9502026-06-10 CRITICAL 9.6 CVE-2026-53476 A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal… Assisted Migration Agent 2026-06-07+ Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45556 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>… Mitigation only Fix from $2,3002026-06-10