Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.6 CVE-2026-41690 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allo… Mitigation only Fix from $1,9502026-05-08 HIGH 8.2 CVE-2026-41693 i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18… Mitigation only Fix from $1,9502026-05-08 MEDIUM 6.5 CVE-2026-41885 i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, … Mitigation only Fix from $1,6002026-05-08 HIGH 7.5 CVE-2026-44340 PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack… Praisonai 4.6.37+ Fix from $1,9502026-05-08 CRITICAL 9.6 CVE-2026-44336 PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou… Praisonai 4.6.34+ Fix from $2,3002026-05-08 HIGH 8.1 CVE-2026-41491 Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-… Dapr 1.15.14 / 1.16.14+ Fix from $1,9502026-05-08 HIGH 7.5 CVE-2026-41493 YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve doc… Yard 0.9.42+ Fix from $1,9502026-05-08 HIGH 7.8 CVE-2026-8069 PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use… Nitrosense 3.00.3198 / 3.01.3056+ Fix from $1,9502026-05-08 HIGH 8.4 CVE-2026-43940 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/… Electerm 3.7.16+ Fix from $1,9502026-05-08 HIGH 8.7 CVE-2026-42275 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restri… Zrok 2.0.2+ Fix from $1,9502026-05-08 MEDIUM 6.3 CVE-2026-8116 A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of the file src/controllers/dxt… Mitigation only Fix from $1,6002026-05-08 MEDIUM 5.3 CVE-2026-8115 A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts … Mitigation only Fix from $1,6002026-05-07 MEDIUM 6.5 CVE-2026-8113 A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vulnerability is the function isP… Miniclaw 2026-03-27+ Fix from $1,6002026-05-07 CRITICAL 9.1 CVE-2026-41691 Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag… I18next Http Backend 3.0.5+ Fix from $2,3002026-05-07 HIGH 7.1 CVE-2026-44243 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can … Gitpython 3.1.48+ Fix from $1,9502026-05-07 CRITICAL 9.6 CVE-2026-41589 Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wis… Wish No fix yet Fix from $2,3002026-05-07 HIGH 8.1 CVE-2026-7252 The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary f… Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.5 CVE-2026-41655 Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template … Mitigation only Fix from $1,6002026-05-07 CRITICAL 9.4 CVE-2026-41202 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.4 CVE-2026-41203 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-40982 Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or … Spring Cloud Config 3.1.14 / 4.1.10+ Fix from $2,3002026-05-07 HIGH 8.8 CVE-2026-40076 OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module … Openmrs after 2.8.5 Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-7875 NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that … Nanoclaw after 1.2.0 Fix from $1,9502026-05-06 MEDIUM 6.5 CVE-2026-43975 FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file p… Wicket 10.9.0+ Fix from $1,6002026-05-06 MEDIUM 6.1 CVE-2026-35254 Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulne… Cloud Infrastructure Cli Mitigation only Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-40075 OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openm… Openmrs after 2.8.5 Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-35397 Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an … Jupyter Server 2.18.0+ Fix from $1,9502026-05-05 CRITICAL 10.0 CVE-2026-7411 In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticat… Mitigation only Fix from $2,3002026-05-05 MEDIUM 6.5 CVE-2026-6262 The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() fu… Mitigation only Fix from $1,6002026-05-05 HIGH 7.3 CVE-2026-43870 Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in… Thrift 0.23.0+ Fix from $1,9502026-05-05