Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2026-7403 A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The … Mitigation only Fix from $1,6002026-04-29 HIGH 7.3 CVE-2026-7404 A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_si… Mitigation only Fix from $1,9502026-04-29 HIGH 7.3 CVE-2026-7400 A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file ser… Patch available Fix from $1,9502026-04-29 HIGH 8.8 CVE-2018-25308 BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files… No fix yet Fix from $1,9502026-04-29 MEDIUM 6.5 CVE-2018-25311 VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers with valid credentials … No fix yet Fix from $1,6002026-04-29 MEDIUM 6.5 CVE-2018-25312 LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by man… No fix yet Fix from $1,6002026-04-29 HIGH 7.3 CVE-2026-7398 A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function… Mitigation only Fix from $1,9502026-04-29 CRITICAL 9.9 CVE-2026-30893 Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path tra… Wazuh 4.14.4+ Fix from $2,3002026-04-29 MEDIUM 5.3 CVE-2026-7396 A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms… Mitigation only Fix from $1,6002026-04-29 HIGH 7.3 CVE-2026-7386 A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manip… Patch available Fix from $1,9502026-04-29 CRITICAL 9.6 CVE-2026-5166 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institu… Mitigation only Fix from $2,3002026-04-29 MEDIUM 6.5 CVE-2026-38993 Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write… Mitigation only Fix from $1,6002026-04-29 HIGH 7.3 CVE-2026-7384 A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c. This impacts … Mitigation only Fix from $1,9502026-04-29 HIGH 7.5 CVE-2026-42520 Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers … Credentials Binding after 719.v80e905ef14eb Fix from $1,9502026-04-29 CRITICAL 9.8 CVE-2026-42249 Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon… Ollama after 0.17.5 Fix from $2,3002026-04-29 HIGH 7.3 CVE-2026-7319 A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_sy… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7314 A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7315 A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the c… Mitigation only Fix from $1,9502026-04-28 MEDIUM 5.9 CVE-2026-7318 A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipu… Mitigation only Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2026-41911 OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace b… Openclaw 2026.4.8+ Fix from $1,6002026-04-28 HIGH 8.1 CVE-2026-41383 OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by … Openclaw 2026.4.2+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7272 A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function genera… Mitigation only Fix from $1,9502026-04-28 MEDIUM 5.3 CVE-2026-7271 A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file se… Patch available Fix from $1,6002026-04-28 MEDIUM 5.3 CVE-2026-7235 A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca1747bf. Affected by this vuln… Mitigation only Fix from $1,6002026-04-28 HIGH 7.3 CVE-2026-7237 A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold… Patch available Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7234 A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/componen… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7216 A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. Impacted is an unknown functi… Mitigation only Fix from $1,9502026-04-28 MEDIUM 5.3 CVE-2026-7217 A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/lis… Mitigation only Fix from $1,6002026-04-28 HIGH 7.3 CVE-2026-7212 A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The ma… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7213 A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file To… Mitigation only Fix from $1,9502026-04-28