Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-5192 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and i… Mitigation only Fix from $1,9502026-05-05 HIGH 7.3 CVE-2026-7811 A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element is the function is_safe_path o… Mitigation only Fix from $1,9502026-05-05 MEDIUM 6.5 CVE-2026-5957 The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traver… Mitigation only Fix from $1,6002026-05-05 HIGH 7.3 CVE-2026-7810 A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_n… Mitigation only Fix from $1,9502026-05-05 HIGH 7.3 CVE-2026-7788 A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the functio… Mitigation only Fix from $1,9502026-05-05 HIGH 7.3 CVE-2026-7784 A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.… Mitigation only Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-6321 fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encod… Fast Uri 3.1.1+ Fix from $1,9502026-05-04 HIGH 8.1 CVE-2026-42075 Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) co… Mitigation only Fix from $1,9502026-05-04 MEDIUM 6.3 CVE-2026-7738 A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-se… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7728 A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0. This vulnerability affects the function get_doc_content/read_doc/update_doc of the comp… Patch available Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7715 A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. This affects the function arango_backup of the file src/tools.ts of the … Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.5 CVE-2026-7645 A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciou… Mitigation only Fix from $1,6002026-05-02 HIGH 7.5 CVE-2026-6320 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is… Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.3 CVE-2026-7627 A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file… Mitigation only Fix from $1,6002026-05-02 MEDIUM 6.3 CVE-2026-7599 A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_to_html of the file mcp-server… Mitigation only Fix from $1,6002026-05-01 HIGH 7.3 CVE-2026-7594 A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the componen… Mitigation only Fix from $1,9502026-05-01 MEDIUM 5.3 CVE-2026-7589 A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_… Mitigation only Fix from $1,6002026-05-01 MEDIUM 5.3 CVE-2026-7588 A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_practices of the file server.py. T… Mitigation only Fix from $1,6002026-05-01 CRITICAL 9.8 CVE-2026-37531 AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the … Automotive Grade Linux after 17.1.12 Fix from $2,3002026-05-01 HIGH 7.3 CVE-2026-7519 A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component En… Mitigation only Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-5656 Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-05-01 MEDIUM 6.5 CVE-2026-3345 IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted… Langflow Desktop after 1.8.4 Fix from $1,6002026-04-30 MEDIUM 6.5 CVE-2026-4502 IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send… Langflow Desktop after 1.8.4 Fix from $1,6002026-04-30 HIGH 8.2 CVE-2026-40912 Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass… Traefik 2.11.43 / 3.6.14+ Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-36762 An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions … Mitigation only Fix from $1,9502026-04-30 CRITICAL 9.6 CVE-2026-36760 An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to ex… Mitigation only Fix from $2,3002026-04-30 CRITICAL 10.0 CVE-2026-36767 A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path vi… Mitigation only Fix from $2,3002026-04-30 HIGH 7.5 CVE-2022-50992 Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpo… Mitigation only Fix from $1,9502026-04-30 CRITICAL 9.8 CVE-2026-22070 ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. Coloros Assistant Mitigation only Fix from $2,3002026-04-30 MEDIUM 6.3 CVE-2026-7445 A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src… Mitigation only Fix from $1,6002026-04-30