Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2025-71211 A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte… Apex One 14.0.0.14136 / 14.0.20315+ Fix from $2,3002026-05-21 CRITICAL 9.9 CVE-2026-4858 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which … Mattermost Server 10.11.15 / 11.4.5+ Fix from $2,3002026-05-21 HIGH 7.6 CVE-2026-44068 Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to… Mitigation only Fix from $1,9502026-05-21 CRITICAL 9.4 CVE-2026-9129 A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.4 CVE-2026-9102 A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa… Mitigation only Fix from $2,3002026-05-20 HIGH 8.7 CVE-2026-39352 Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Pat… Mitigation only Fix from $1,9502026-05-20 CRITICAL 9.4 CVE-2026-39405 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with cour… Mitigation only Fix from $2,3002026-05-20 HIGH 7.5 CVE-2026-24208 NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerabil… Triton Inference Server 26.03+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-24209 NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerabil… Triton Inference Server 26.03+ Fix from $1,9502026-05-20 MEDIUM 6.8 CVE-2026-35593 Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 an… Mitigation only Fix from $1,6002026-05-20 CRITICAL 9.8 CVE-2026-36829 An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session… Mitigation only Fix from $2,3002026-05-19 HIGH 7.3 CVE-2025-70950 An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request. Mitigation only Fix from $1,9502026-05-19 MEDIUM 5.9 CVE-2026-46724 The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents … Mitigation only Fix from $1,6002026-05-19 MEDIUM 6.1 CVE-2026-31379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-29220 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befor… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 CRITICAL 9.1 CVE-2026-45230 DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allow… Patch available Fix from $2,3002026-05-18 HIGH 7.5 CVE-2026-29963 HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text … Mailinspector Mitigation only Fix from $1,9502026-05-18 MEDIUM 6.5 CVE-2026-20685 An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation.… Private Cloud Compute 5e290.3+ Fix from $1,6002026-05-18 HIGH 7.5 CVE-2026-6381 The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to per… Mitigation only Fix from $1,9502026-05-18 MEDIUM 6.5 CVE-2026-8765 A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/ki… Kilo Code after 7.0.47 Fix from $1,6002026-05-17 CRITICAL 9.1 CVE-2026-8757 A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.… Hive after 0.11.0 Fix from $2,3002026-05-17 MEDIUM 6.3 CVE-2026-8754 A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of … Patch available Fix from $1,6002026-05-17 HIGH 7.3 CVE-2026-8755 A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of… Mitigation only Fix from $1,9502026-05-17 HIGH 7.3 CVE-2026-8756 A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_… Mitigation only Fix from $1,9502026-05-17 HIGH 7.5 CVE-2018-25326 Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting dir… No fix yet Fix from $1,9502026-05-17 HIGH 7.5 CVE-2018-25325 Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unesca… No fix yet Fix from $1,9502026-05-17 HIGH 7.5 CVE-2021-47977 WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attac… No fix yet Fix from $1,9502026-05-16 HIGH 8.8 CVE-2021-47979 WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by ma… No fix yet Fix from $1,9502026-05-16 HIGH 7.5 CVE-2021-47942 Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive… Home Assistant Community Store 1.10.0+ Fix from $1,9502026-05-16 HIGH 8.1 CVE-2026-44565 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the… Open Webui 0.6.10+ Fix from $1,9502026-05-15