Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.7 CVE-2026-34242 Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following … Weblate 5.17+ Fix from $1,9502026-04-15 HIGH 7.5 CVE-2026-30996 An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbit… Mitigation only Fix from $1,9502026-04-15 CRITICAL 9.9 CVE-2026-20180EPSS 6% A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… Identity Services Engine 3.2.0+ Fix from $2,3002026-04-15 HIGH 7.1 CVE-2026-40090 Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf pa… Zarf 0.74.2+ Fix from $1,9502026-04-15 MEDIUM 6.5 CVE-2025-15470 The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in the akd_required_plugin_callbac… Mitigation only Fix from $1,6002026-04-15 CRITICAL 9.6 CVE-2026-39399 NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi… Patch available Fix from $2,3002026-04-14 HIGH 8.8 CVE-2026-35031 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V… Jellyfin 10.11.7+ Fix from $1,9502026-04-14 HIGH 7.7 CVE-2026-34619EPSS 9% ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $1,9502026-04-14 HIGH 8.6 CVE-2026-27305EPSS 29% ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $1,9502026-04-14 MEDIUM 6.1 CVE-2026-2399 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritte… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 MEDIUM 6.7 CVE-2026-25691 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSan… Fortisandbox 4.4.9 / 5.0.6+ Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2026-22573 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, Forti… Fortisoar after 7.6.3 Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2025-68649 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiA… Fortimanager Cloud 7.4.8 / 7.6.5+ Fix from $1,6002026-04-14 MEDIUM 6.5 CVE-2025-61624 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, For… Fortios 1.7.1 / 7.0.7+ Fix from $1,6002026-04-14 HIGH 7.2 CVE-2026-6227 The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST en… Mitigation only Fix from $1,9502026-04-14 CRITICAL 9.8 CVE-2026-22562 A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on t… Mitigation only Fix from $2,3002026-04-13 HIGH 7.8 CVE-2026-32146 Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependen… Gleam 1.15.4+ Fix from $1,9502026-04-11 MEDIUM 6.5 CVE-2026-3689 OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on … Openclaw 2026.2.21+ Fix from $1,6002026-04-11 HIGH 7.5 CVE-2026-40180 Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzi… Quarkus Openapi Generator 2.15.0+ Fix from $1,9502026-04-10 HIGH 8.2 CVE-2026-40163 Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes… Saltcorn 1.4.5 / 1.5.5+ Fix from $1,9502026-04-10 HIGH 8.3 CVE-2026-31939 Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file fe… Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-40157 PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() withou… Praisonai 4.5.128+ Fix from $1,9502026-04-10 MEDIUM 5.3 CVE-2026-40086 Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote a… Rembg 2.0.75+ Fix from $1,6002026-04-10 HIGH 7.7 CVE-2026-35668 OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other… Openclaw 2026.3.24+ Fix from $1,9502026-04-10 CRITICAL 9.8 CVE-2026-6057 FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrar… Patch available Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6024 A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP … I6 Firmware Mitigation only Fix from $2,3002026-04-10 MEDIUM 5.3 CVE-2026-5998 A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of t… Patch available Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-4351 The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This i… Mitigation only Fix from $1,9502026-04-10 MEDIUM 5.3 CVE-2026-40152 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspac… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-09 MEDIUM 6.3 CVE-2026-39977 flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user d… Flatpak Builder 1.4.8+ Fix from $1,6002026-04-09