Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.5 CVE-2026-41612 Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. Live Preview 0.4.19+ Fix from $1,6002026-05-12 CRITICAL 9.6 CVE-2026-42048 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle… Langflow 1.9.0+ Fix from $2,3002026-05-12 HIGH 8.5 CVE-2026-43989 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age… Patch available Fix from $1,9502026-05-12 HIGH 7.1 CVE-2026-6865 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitiv… No fix yet Fix from $1,9502026-05-12 MEDIUM 6.8 CVE-2026-43901 Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 an… Wireshark Mcp after 1.1.5 Fix from $1,6002026-05-11 HIGH 8.7 CVE-2026-43888 Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by pa… Mitigation only Fix from $1,9502026-05-11 HIGH 8.2 CVE-2026-42564 jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-ic… Mitigation only Fix from $1,9502026-05-11 MEDIUM 6.9 CVE-2026-42888 Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.… Mitigation only Fix from $1,6002026-05-11 HIGH 7.8 CVE-2026-28915 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS So… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 CRITICAL 9.4 CVE-2026-42882 oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path inte… Patch available Fix from $2,3002026-05-11 HIGH 7.5 CVE-2026-2614 A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthe… Mlflow 3.10.0+ Fix from $1,9502026-05-11 HIGH 7.1 CVE-2026-45224 Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolut… Patch available Fix from $1,9502026-05-11 MEDIUM 6.7 CVE-2026-42866 Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write_json, and (commented-but-shi… Mitigation only Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-42314 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient s… Pyload Ng 0.5.0b3.dev100+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-42315 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() AP… Pyload Ng 0.5.0b3.dev100+ Fix from $1,6002026-05-11 MEDIUM 5.9 CVE-2026-6815 An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated… Casdoor after 2.328.0 Fix from $1,6002026-05-11 CRITICAL 9.1 CVE-2026-42608 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulatin… Grav 2.0.0+ Fix from $2,3002026-05-11 HIGH 7.5 CVE-2025-65418 docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url. Mitigation only Fix from $1,9502026-05-11 HIGH 7.2 CVE-2026-41951 Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an… Mitigation only Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-8274 A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of the file cramfsck.c of the comp… Patch available Fix from $1,6002026-05-11 MEDIUM 6.2 CVE-2022-50956 WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files … No fix yet Fix from $1,6002026-05-10 MEDIUM 5.3 CVE-2026-8215 A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This vulnerability affects the function iasRequestFileEvent of… Mitigation only Fix from $1,6002026-05-10 HIGH 8.8 CVE-2026-42605 AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js med… Azuracast 0.23.6+ Fix from $1,9502026-05-09 HIGH 7.5 CVE-2026-42574 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk coul… Patch available Fix from $1,9502026-05-09 HIGH 7.5 CVE-2026-42351 pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concate… Patch available Fix from $1,9502026-05-08 MEDIUM 5.1 CVE-2026-42213 SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th… Patch available Fix from $1,6002026-05-08 HIGH 8.8 CVE-2026-7807 SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that all… Smartermail 100.0.9560+ Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-42028 novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenti… Patch available Fix from $1,6002026-05-08 CRITICAL 9.8 CVE-2026-38360EPSS 6% Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash… Patch available Fix from $2,3002026-05-08 HIGH 8.2 CVE-2026-42353 i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18… Mitigation only Fix from $1,9502026-05-08