Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.1 CVE-2026-73291 Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-67286 Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attac… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-66381 A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. No fix yet Fix from $4,0002026-08-12 CRITICAL 9.2 CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can p… No fix yet Fix from $5,7502026-08-12 HIGH 8.1 CVE-2026-19594 Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation thro… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-63134 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-73244 kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/sr… No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-73234 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp co… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-73034 DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s… No fix yet Fix from $5,7502026-08-11 MEDIUM 5.0 CVE-2026-71475 A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat… No fix yet Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-19091 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due t… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-73225 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP … No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-73227 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server t… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-73223 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server … No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72713 XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitra… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-48441 Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a… Lightroom 15.5+ Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-65768 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec… Teams 1.0.0.2026133602+ Fix from $5,7502026-08-11 HIGH 7.1 CVE-2026-48442 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could res… C2pa 0.12.1 / 0.27.6+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-48446 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lea… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-32677 Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivil… No fix yet Fix from $4,0002026-08-11 HIGH 8.5 CVE-2026-73079 Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform … No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18640 The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.2 CVE-2026-72783 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContain… No fix yet Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-72770 n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72602 A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listin… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-72604 A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server v… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.0 CVE-2026-33922 A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an i… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.9 CVE-2026-66777 SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r… No fix yet Fix from $4,0002026-08-11 HIGH 7.6 CVE-2026-44763 SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using s… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-73030 unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize … No fix yet Fix from $4,9002026-08-10