Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.8 CVE-2026-52752 Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Att… Ghidra 12.0.2+ Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-52755 Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the inten… Ghidra 12.0.4+ Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-52756 Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied … Ghidra after 12.1.2 Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-24717 A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator accoun… Qts 5.2.9.3492+ Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-44716 Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1… Pipecat 1.2.0+ Fix from $1,9502026-06-10 HIGH 8.6 CVE-2026-46491 SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module… Patch available Fix from $1,9502026-06-10 MEDIUM 5.5 CVE-2026-34657 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direct… C2pa after 0.80.1 Fix from $1,6002026-06-09 HIGH 8.8 CVE-2026-47932 ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $1,9502026-06-09 MEDIUM 5.3 CVE-2026-36726 An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete … Mitigation only Fix from $1,6002026-06-09 HIGH 8.8 CVE-2026-36723 An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory tra… Mitigation only Fix from $1,9502026-06-09 HIGH 7.7 CVE-2026-49957 Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-roo… Patch available Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-45482 Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attack… Visual Studio Code 1.123.2+ Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-45454 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execut… Sharepoint Server 16.0.19725.20384+ Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-32193 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to… Azure Kubernetes Service 2026-02-13.5+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-22926 Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. Mitigation only Fix from $1,9502026-06-09 HIGH 7.5 CVE-2017-20248 Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating t… No fix yet Fix from $1,9502026-06-09 HIGH 7.5 CVE-2017-20250 Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the a… No fix yet Fix from $1,9502026-06-09 HIGH 7.1 CVE-2026-49742 Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media … Patch available Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-49818 The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec… Apache Airflow Providers Samba 4.12.6+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-41972 Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability. No fix yet Fix from $1,6002026-06-09 MEDIUM 5.9 CVE-2026-41843 Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,6002026-06-09 HIGH 8.1 CVE-2026-46484 Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / author… Mitigation only Fix from $1,9502026-06-08 MEDIUM 5.3 CVE-2026-46486 MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise. Prior to versio… Mitigation only Fix from $1,6002026-06-08 CRITICAL 9.4 CVE-2026-41448 AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full… Mitigation only Fix from $2,3002026-06-08 HIGH 8.8 CVE-2026-25559 OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arb… Mitigation only Fix from $1,9502026-06-08 HIGH 7.5 CVE-2026-49233 Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This … Routinator 0.15.2+ Fix from $1,9502026-06-08 HIGH 8.7 CVE-2026-9506 This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remo… Mitigation only Fix from $1,9502026-06-08 MEDIUM 6.2 CVE-2022-50953 WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files b… No fix yet Fix from $1,6002026-06-08 MEDIUM 6.3 CVE-2026-11470 A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-syst… Patch available Fix from $1,6002026-06-08 MEDIUM 5.4 CVE-2026-11467 A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the fil… Mitigation only Fix from $1,6002026-06-08