Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.3 CVE-2026-19758 A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of… No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19757 A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the co… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.3 CVE-2026-19756 A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the compo… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-73658 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-73659 Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-72850 Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p… No fix yet Fix from $5,7502026-08-13 HIGH 7.5 CVE-2026-17473 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a res… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.9 CVE-2026-45774 compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profil… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-48099 WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-16908 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul… I No fix yet Fix from $4,9002026-08-13 CRITICAL 9.4 CVE-2026-73653 Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta… No fix yet Fix from $5,7502026-08-13 HIGH 8.2 CVE-2026-13048 Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon … No fix yet Fix from $4,9002026-08-13 HIGH 7.6 CVE-2026-73509 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-70460 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with… No fix yet Fix from $4,9002026-08-13 HIGH 7.7 CVE-2026-65582 Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-61980 Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-28189 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-73620 GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe opt… No fix yet Fix from $4,9002026-08-13 HIGH 7.7 CVE-2026-73498 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment pa… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-64826 rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized di… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.9 CVE-2026-66898 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing … No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-13105 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. I Access Client Solutions No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-13622 A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside… No fix yet Fix from $4,9002026-08-12 HIGH 8.5 CVE-2026-16033 A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image me… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.0 CVE-2026-73407 Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials … No fix yet Fix from $5,7502026-08-12 HIGH 7.6 CVE-2026-73327 Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a craft… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-17266 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to … I after 7.6 Fix from $4,0002026-08-12 HIGH 7.1 CVE-2026-17094 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal… I Fix unknown Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-66384 An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 6.8 CVE-2026-65939 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within … No fix yet Fix from $4,0002026-08-12