Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.1 CVE-2026-34745 Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/up… Fireshare 1.5.3+ Fix from $2,3002026-04-02 MEDIUM 5.5 CVE-2026-34730 Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load Y… Copier 9.14.1+ Fix from $1,6002026-04-02 MEDIUM 6.5 CVE-2026-34591 Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to di… Poetry 2.3.3+ Fix from $1,6002026-04-02 HIGH 8.1 CVE-2026-34522 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Sillytavern 1.17.0+ Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-34523 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Sillytavern 1.17.0+ Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-34524 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Sillytavern 1.17.0+ Fix from $1,9502026-04-02 MEDIUM 6.3 CVE-2026-5344 A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt_uploadImage of the file rpc/… Mitigation only Fix from $1,6002026-04-02 HIGH 8.1 CVE-2026-34790 Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter … Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.1 CVE-2026-34728 phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the medi… Phpmyfaq 4.1.1+ Fix from $1,9502026-04-02 HIGH 8.1 CVE-2026-4347 The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' … Mitigation only Fix from $1,9502026-04-02 HIGH 7.2 CVE-2026-3987 A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execut… Fireware 12.12 / 2026.2+ Fix from $1,9502026-04-01 MEDIUM 6.5 CVE-2026-34750 Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, … Payload 3.78.0+ Fix from $1,6002026-04-01 MEDIUM 5.5 CVE-2026-34446 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.loa… Onnx 1.21.0+ Fix from $1,6002026-04-01 MEDIUM 5.5 CVE-2026-34447 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal … Onnx 1.21.0+ Fix from $1,6002026-04-01 HIGH 7.5 CVE-2026-27489 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerabilit… Onnx 1.21.0+ Fix from $1,9502026-04-01 HIGH 8.3 CVE-2026-34603 Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media rout… Tinacms\/cli after 2.2.1 Fix from $1,9502026-04-01 HIGH 8.8 CVE-2026-34604 Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge.… Tinacms\/graphql after 2.2.1 Fix from $1,9502026-04-01 HIGH 8.1 CVE-2026-33949 Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users… Tinacms\/graphql after 2.2.1 Fix from $1,9502026-04-01 HIGH 7.2 CVE-2026-27101 Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper Limitation of a Pathname … Secure Connect Gateway 5.34.00.00+ Fix from $1,9502026-04-01 HIGH 7.1 CVE-2026-28265 PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this v… Powerstoreos 4.4.0.0-2692403+ Fix from $1,9502026-04-01 HIGH 7.3 CVE-2026-5258 A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the compon… Mitigation only Fix from $1,9502026-04-01 MEDIUM 5.4 CVE-2026-34451 Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before ver… Claude Sdk For Typescript 0.81.0+ Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2026-30285 An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the fil… Zora Mitigation only Fix from $2,3002026-03-31 HIGH 8.4 CVE-2026-30290 An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the f… Intouch Contacts \& Caller Id No fix yet Fix from $1,9502026-03-31 HIGH 8.4 CVE-2026-30279 An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files … My Location Mitigation only Fix from $1,9502026-03-31 CRITICAL 9.0 CVE-2026-30282 An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files vi… Cast To Tv Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30283 An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal fi… Animal Sounds And Ringtones Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30286 An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via t… Zefiro Mitigation only Fix from $2,3002026-03-31 HIGH 8.4 CVE-2026-30277 An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal file… Mobile Print Mitigation only Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-30278 An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file… Fly Is Fun Mitigation only Fix from $2,3002026-03-31