Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.6 CVE-2024-40646 Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc9… Vertex 2024-07-17+ Fix from $1,9502026-06-01 HIGH 7.1 CVE-2026-48827 Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operati… Mina Sshd 2.18.0+ Fix from $1,9502026-06-01 MEDIUM 6.4 CVE-2026-40547 SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-10213 A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the comp… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.5 CVE-2018-25421 Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file par… No fix yet Fix from $1,6002026-05-30 HIGH 7.5 CVE-2018-25408 The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to downlo… No fix yet Fix from $1,9502026-05-30 CRITICAL 9.1 CVE-2026-44650 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $2,3002026-05-29 HIGH 7.7 CVE-2026-47179 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns t… Patch available Fix from $1,9502026-05-29 CRITICAL 9.9 CVE-2026-45661 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.3 CVE-2026-45668 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malic… Mitigation only Fix from $2,3002026-05-29 HIGH 7.5 CVE-2026-10108 xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated att… Patch available Fix from $1,9502026-05-29 HIGH 7.2 CVE-2026-39276 The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP co… Emlog No fix yet Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2018-25393 Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory travers… No fix yet Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2026-46337 WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk… Avideo after 29.0 Fix from $1,6002026-05-29 CRITICAL 9.9 CVE-2026-9559 A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw … Mitigation only Fix from $2,3002026-05-29 MEDIUM 5.5 CVE-2026-44885 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8+ Fix from $1,6002026-05-28 HIGH 8.1 CVE-2026-44973 Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. In… Mitigation only Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-49128 Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 with… Patch available Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-32847 DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthentica… Deepcode after 1.2.0 Fix from $1,9502026-05-28 HIGH 7.3 CVE-2026-33462 A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could cr… Kibana 8.19.16 / 9.3.5+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-4944 vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files… Mitigation only Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-45017 Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not g… Python Liquid 2.2.0+ Fix from $1,9502026-05-28 HIGH 8.7 CVE-2026-44593 esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacy… Mitigation only Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-44594 esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the… Mitigation only Fix from $1,9502026-05-28 HIGH 8.4 CVE-2026-49238 An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root pr… Multipass 1.16.3+ Fix from $1,9502026-05-28 HIGH 8.5 CVE-2026-9789 A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P… Mitigation only Fix from $1,9502026-05-28 HIGH 8.1 CVE-2026-46402 Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-contro… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44635 Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metachara… Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-44353 Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do… Streamlink 8.4.0+ Fix from $1,6002026-05-27 MEDIUM 5.4 CVE-2026-45571 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could all… Go Git 5.19.1+ Fix from $1,6002026-05-27