Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-9290 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… Patch available Fix from $1,9502026-06-06 HIGH 8.1 CVE-2026-11416 MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path i… Patch available Fix from $1,9502026-06-05 CRITICAL 10.0 CVE-2026-11429 Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi… Mitigation only Fix from $2,3002026-06-05 HIGH 8.3 CVE-2026-11431 A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated u… Mitigation only Fix from $1,9502026-06-05 CRITICAL 9.4 CVE-2026-11423 A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in th… Mitigation only Fix from $2,3002026-06-05 MEDIUM 6.5 CVE-2026-46397 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerabili… Mitigation only Fix from $1,6002026-06-05 CRITICAL 9.8 CVE-2026-11414 A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 HIGH 8.8 CVE-2026-11419 A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled … On Prem Enterprise Server 8.1.1+ Fix from $1,9502026-06-05 CRITICAL 9.8 CVE-2026-11420 Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 CRITICAL 9.1 CVE-2026-36500 An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted reques… Mitigation only Fix from $2,3002026-06-05 HIGH 7.5 CVE-2026-50234 Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directo… Mitigation only Fix from $1,9502026-06-05 MEDIUM 6.4 CVE-2026-10732 All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive contain… Patch available Fix from $1,6002026-06-05 MEDIUM 6.9 CVE-2026-7774 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive me… Patch available Fix from $1,6002026-06-04 MEDIUM 5.7 CVE-2026-40605 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache d… Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.5 CVE-2019-25740 Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom … No fix yet Fix from $1,6002026-06-04 CRITICAL 9.8 CVE-2019-25727 WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive f… Mitigation only Fix from $2,3002026-06-04 HIGH 7.8 CVE-2026-50207 The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellula… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-35082 The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied … Universal Gateway Firmware 6_00_07+ Fix from $1,9502026-06-03 MEDIUM 6.5 CVE-2026-49144 BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated n… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.5 CVE-2026-35718 A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to … Fd8136 Firmware Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.6 CVE-2026-43965 Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content.… Patch available Fix from $1,6002026-06-02 MEDIUM 6.2 CVE-2026-0055 In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-49136 Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI servic… Patch available Fix from $1,9502026-06-01 HIGH 8.8 CVE-2026-45727 CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint quer… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-45279 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, … Nextcloud Server 28.0.14.15 / 29.0.17.12+ Fix from $1,6002026-06-01 HIGH 8.2 CVE-2026-43624 F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write … Patch available Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10278 A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.5 CVE-2026-8643 pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation dire… Pip 26.1.2+ Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2026-42679 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Travers… No fix yet Fix from $1,6002026-06-01 CRITICAL 9.6 CVE-2026-48866 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal… Mitigation only Fix from $2,3002026-06-01