Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2026-6968 Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file… Tough 0.15.0 / 0.22.0+ Fix from $1,6002026-04-24 HIGH 8.4 CVE-2026-41433 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java … Opentelemetry Ebpf Instrumentation 0.8.0+ Fix from $1,9502026-04-24 HIGH 7.1 CVE-2026-41894 SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePat… Patch available Fix from $1,9502026-04-24 HIGH 7.6 CVE-2026-41419 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board… Mitigation only Fix from $1,9502026-04-24 HIGH 8.7 CVE-2026-41140 Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs w… Mitigation only Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-33076 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p… Roxy Wi 8.2.6.4+ Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-33077 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the hapro… Roxy Wi 8.2.6.4+ Fix from $1,9502026-04-24 MEDIUM 6.1 CVE-2026-29050 melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can i… Melange 0.43.4+ Fix from $1,6002026-04-24 HIGH 7.1 CVE-2026-6940 radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary direct… Radare2 6.1.4+ Fix from $1,9502026-04-23 HIGH 7.8 CVE-2026-6941 radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the… Radare2 6.1.4+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-41205 Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with /… Mako 1.3.11+ Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-6903 The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated… Mitigation only Fix from $1,9502026-04-23 CRITICAL 10.0 CVE-2026-41211 Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` … Vite\+ 0.1.17+ Fix from $2,3002026-04-23 HIGH 7.5 CVE-2026-41180 PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates th… Patch available Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-40062 A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the ope… Ziostation2 after 2.9.8.7 Fix from $1,9502026-04-23 CRITICAL 9.1 CVE-2026-33656 EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing … Espocrm 9.3.4+ Fix from $2,3002026-04-22 HIGH 7.1 CVE-2026-34414 Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinde… Patch available Fix from $1,9502026-04-22 MEDIUM 5.6 CVE-2026-35363 A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the … Coreutils No fix yet Fix from $1,6002026-04-22 HIGH 7.3 CVE-2026-35338 A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validat… Coreutils 0.6.0+ Fix from $1,9502026-04-22 CRITICAL 9.1 CVE-2026-32885 DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction … Ddev 1.25.2+ Fix from $2,3002026-04-22 HIGH 7.1 CVE-2026-6855 A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_… Instructlab Mitigation only Fix from $1,9502026-04-22 MEDIUM 6.5 CVE-2026-4280 The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_a… Mitigation only Fix from $1,6002026-04-22 HIGH 8.1 CVE-2026-41058 WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not a… Avideo after 29.0 Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-41062 WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVi… Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 8.1 CVE-2026-6832 Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete file… Hermes Web Ui 0.50.32+ Fix from $1,9502026-04-21 MEDIUM 6.3 CVE-2026-6829 nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an … Patch available Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-40923 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3… Tekton Pipelines 1.11.1+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-40909 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by dire… Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 8.8 CVE-2026-40876 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authe… Goshs 2.0.0+ Fix from $1,9502026-04-21 CRITICAL 9.1 CVE-2026-41193 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives… Patch available Fix from $2,3002026-04-21