Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2026-44566 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp,… Open Webui 0.1.124+ Fix from $2,3002026-05-15 MEDIUM 5.5 CVE-2026-46383 Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archiv… No fix yet Fix from $1,6002026-05-15 HIGH 7.1 CVE-2026-44641 Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by … Mitigation only Fix from $1,9502026-05-15 CRITICAL 9.2 CVE-2026-7182 Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the ht… Mitigation only Fix from $2,3002026-05-15 HIGH 7.5 CVE-2026-41552 PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated … Pdf Export Module 0.7.6+ Fix from $1,9502026-05-15 HIGH 7.5 CVE-2026-6403 The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path val… Mitigation only Fix from $1,9502026-05-15 HIGH 7.1 CVE-2026-44647 OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected boundary between repository-cont… Mitigation only Fix from $1,9502026-05-14 HIGH 8.6 CVE-2026-44522 Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload ass… No fix yet Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-27886 Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer… Strapi 5.37.0+ Fix from $1,9502026-05-14 CRITICAL 9.1 CVE-2026-44542 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined wi… Filebrowser Quantum 1.3.1 / 1.3.9+ Fix from $2,3002026-05-14 MEDIUM 6.9 CVE-2026-42598 Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when request… Mitigation only Fix from $1,6002026-05-14 MEDIUM 5.3 CVE-2026-42593 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert… Gotenberg 8.32.0+ Fix from $1,6002026-05-14 HIGH 8.4 CVE-2026-42881 STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) wit… Mitigation only Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-6670 The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the 'sub_dir' and 'media_items' p… Mitigation only Fix from $1,6002026-05-14 MEDIUM 5.7 CVE-2026-44440 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restric… Erpnext 15.101.1 / 16.10.0+ Fix from $1,6002026-05-13 MEDIUM 6.1 CVE-2026-44437 The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a… Angular Cli 19.2.25 / 20.3.25+ Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-44373 Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path trav… Nitro 2.13.4 / 3.0.260429+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-22677 Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbi… Patch available Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-6282 A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenti… Mitigation only Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-31156 A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp… Openplc V3 Firmware No fix yet Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-20916 An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG… Big Iq Centralized Management Mitigation only Fix from $1,9502026-05-13 HIGH 7.5 CVE-2020-37219 Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating t… No fix yet Fix from $1,9502026-05-13 HIGH 8.7 CVE-2026-44307 Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the dir… Patch available Fix from $1,9502026-05-12 HIGH 7.6 CVE-2026-45225 Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled f… Patch available Fix from $1,9502026-05-12 HIGH 8.1 CVE-2026-44301 Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, Tailwin… Hugo 0.161.0+ Fix from $1,9502026-05-12 CRITICAL 9.9 CVE-2026-42196 django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal … Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-7474EPSS 7% HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnera… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.3 CVE-2026-44225 Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every … Mitigation only Fix from $2,3002026-05-12 HIGH 8.7 CVE-2026-34653 Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Path… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12 MEDIUM 6.3 CVE-2026-34664 Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') … Substance 3d Designer after 15.1.0 Fix from $1,6002026-05-12