Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.3 CVE-2026-7214 A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/fi… Mitigation only Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-7205 A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the … Mitigation only Fix from $1,9502026-04-28 MEDIUM 6.5 CVE-2026-41370 OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbou… Openclaw 2026.3.31+ Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2026-41363 OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses… Openclaw 2026.3.28+ Fix from $1,6002026-04-28 MEDIUM 5.3 CVE-2026-7179 A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_null_terminated_string of the fi… Mitigation only Fix from $1,6002026-04-27 HIGH 7.3 CVE-2026-7159 A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Perf… Mitigation only Fix from $1,9502026-04-27 HIGH 7.5 CVE-2026-3087 If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted o… Python after 3.14.4 Fix from $1,9502026-04-27 HIGH 7.3 CVE-2026-7149 A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepar… Mitigation only Fix from $1,9502026-04-27 HIGH 8.8 CVE-2026-41463 ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated att… Mitigation only Fix from $1,9502026-04-27 MEDIUM 6.5 CVE-2026-41465 ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter … Mitigation only Fix from $1,6002026-04-27 HIGH 7.5 CVE-2026-30351 A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files via sending … Mitigation only Fix from $1,9502026-04-27 MEDIUM 5.3 CVE-2026-7132 A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The… Mitigation only Fix from $1,6002026-04-27 MEDIUM 5.0 CVE-2026-7085 A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/abo… Mitigation only Fix from $1,6002026-04-27 MEDIUM 5.3 CVE-2026-7059 A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of… Mitigation only Fix from $1,6002026-04-26 CRITICAL 9.8 CVE-2026-7036 A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP… I9 Firmware Mitigation only Fix from $2,3002026-04-26 MEDIUM 5.4 CVE-2026-7024 A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the fil… Mitigation only Fix from $1,6002026-04-26 MEDIUM 6.5 CVE-2026-6968 Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file… Tough 0.15.0 / 0.22.0+ Fix from $1,6002026-04-24 HIGH 8.4 CVE-2026-41433 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java … Opentelemetry Ebpf Instrumentation 0.8.0+ Fix from $1,9502026-04-24 HIGH 7.1 CVE-2026-41894 SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePat… Patch available Fix from $1,9502026-04-24 HIGH 7.6 CVE-2026-41419 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board… Mitigation only Fix from $1,9502026-04-24 HIGH 8.7 CVE-2026-41140 Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs w… Mitigation only Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-33076 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p… Roxy Wi 8.2.6.4+ Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-33077 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the hapro… Roxy Wi 8.2.6.4+ Fix from $1,9502026-04-24 MEDIUM 6.1 CVE-2026-29050 melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can i… Melange 0.43.4+ Fix from $1,6002026-04-24 HIGH 7.1 CVE-2026-6940 radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary direct… Radare2 6.1.4+ Fix from $1,9502026-04-23 HIGH 7.8 CVE-2026-6941 radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the… Radare2 6.1.4+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-41205 Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with /… Mako 1.3.11+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-6903 The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated… Mitigation only Fix from $1,9502026-04-23 CRITICAL 10.0 CVE-2026-41211 Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` … Vite\+ 0.1.17+ Fix from $2,3002026-04-23 HIGH 7.5 CVE-2026-41180 PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates th… Patch available Fix from $1,9502026-04-23