Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2026-40611 Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrar… Mitigation only Fix from $1,9502026-04-21 CRITICAL 9.4 CVE-2026-40576 excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions u… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-40050 CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne… Mitigation only Fix from $2,3002026-04-21 HIGH 7.1 CVE-2026-39973 Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decode… Apktool 3.0.2+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-39378 The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when … Nbconvert 7.17.1+ Fix from $1,6002026-04-21 CRITICAL 10.0 CVE-2026-39861 Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks poin… Claude Code 2.1.64+ Fix from $2,3002026-04-21 MEDIUM 6.5 CVE-2026-39377 The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arb… Nbconvert 7.17.1+ Fix from $1,6002026-04-21 HIGH 8.4 CVE-2026-35570 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `b… Openclaude 0.5.1+ Fix from $1,9502026-04-21 HIGH 8.1 CVE-2026-5478 The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to … Mitigation only Fix from $1,9502026-04-20 HIGH 8.1 CVE-2026-6248 The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding … Mitigation only Fix from $1,9502026-04-20 HIGH 7.5 CVE-2026-41245 Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attack… Junrar 7.5.10+ Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6620 A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the com… Mitigation only Fix from $1,6002026-04-20 HIGH 8.1 CVE-2026-5966 ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can expl… Threatsonar Anti Ransomware 4.0.0+ Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6615 A weakness has been identified in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function Upload of the file superagi/contro… Mitigation only Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6568 A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controlle… Mitigation only Fix from $1,9502026-04-19 HIGH 7.8 CVE-2026-40491 gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functi… Gdown 5.2.2+ Fix from $1,9502026-04-18 CRITICAL 9.1 CVE-2026-40258 The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerabil… Patch available Fix from $2,3002026-04-17 CRITICAL 9.9 CVE-2026-40342 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con… Firebird 3.0.14 / 4.0.7+ Fix from $2,3002026-04-17 HIGH 7.5 CVE-2026-5710 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in vers… Mitigation only Fix from $1,9502026-04-17 CRITICAL 9.1 CVE-2026-40518 ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation whe… Deerflow Patch available Fix from $2,3002026-04-17 HIGH 8.8 CVE-2026-3464 The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_att… Mitigation only Fix from $1,9502026-04-17 MEDIUM 5.4 CVE-2026-6496 A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POS… Mitigation only Fix from $1,6002026-04-17 HIGH 7.5 CVE-2026-4659 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up… Mitigation only Fix from $1,9502026-04-17 HIGH 7.8 CVE-2026-41082 In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. Debian Linux 2.5.1+ Fix from $1,9502026-04-16 MEDIUM 5.3 CVE-2026-6410 @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function … Fastify Static 9.1.1+ Fix from $1,6002026-04-16 HIGH 8.8 CVE-2025-14868 The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all vers… Mitigation only Fix from $1,9502026-04-16 MEDIUM 6.5 CVE-2026-40503 OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files… Openharness 2026-04-13+ Fix from $1,6002026-04-16 MEDIUM 5.3 CVE-2026-21726 The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can … Loki 3.6.4+ Fix from $1,6002026-04-15 MEDIUM 5.0 CVE-2026-40256 Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolu… Weblate 5.17+ Fix from $1,6002026-04-15 MEDIUM 6.8 CVE-2026-33220 Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe… Weblate 5.17+ Fix from $1,6002026-04-15