Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.6 CVE-2026-33581 OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using me… Openclaw 2026.3.24+ Fix from $1,9502026-03-31 HIGH 7.6 CVE-2026-29870 A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir pa… Mitigation only Fix from $1,9502026-03-31 CRITICAL 9.1 CVE-2025-10559 A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Rele… 3dexperience Mitigation only Fix from $2,3002026-03-31 HIGH 7.5 CVE-2026-34070 LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.load… Langchain Core 1.2.22+ Fix from $1,9502026-03-31 MEDIUM 6.5 CVE-2026-32727 SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack wh… Scitokens Library 1.9.7+ Fix from $1,6002026-03-31 HIGH 7.2 CVE-2026-30940 baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/a… Basercms 5.2.3+ Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-27018 Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case … Gotenberg 8.29.0+ Fix from $1,9502026-03-30 MEDIUM 6.5 CVE-2026-33027 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversa… Nginx Ui 2.3.4+ Fix from $1,6002026-03-30 CRITICAL 10.0 CVE-2025-15036 A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf… Mlflow 3.9.0+ Fix from $2,3002026-03-30 MEDIUM 5.3 CVE-2026-5014 A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log/ of the component Wildcard H… Mitigation only Fix from $1,6002026-03-28 MEDIUM 5.3 CVE-2026-5013 A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key. The manipulation of the arg… Mitigation only Fix from $1,6002026-03-28 MEDIUM 6.3 CVE-2026-4999 A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile… Mitigation only Fix from $1,6002026-03-28 MEDIUM 5.3 CVE-2026-4997 A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql… Mitigation only Fix from $1,6002026-03-28 HIGH 8.4 CVE-2016-20048 iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized val… No fix yet Fix from $1,9502026-03-28 HIGH 8.4 CVE-2016-20040 TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application o… No fix yet Fix from $1,9502026-03-28 HIGH 8.4 CVE-2016-20041 Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an … No fix yet Fix from $1,9502026-03-28 MEDIUM 6.5 CVE-2026-33989 Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Trav… Mobile Mcp 0.0.49+ Fix from $1,6002026-03-27 HIGH 8.8 CVE-2026-5027EPSS 33% The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arb… Langflow 1.9.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33748 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insuf… Buildkit 0.28.1+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-29871 A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong … Awesome Llm Apps 2026-01-19+ Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-4619 Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. Aterm Wx3600hp Firmware 1.5.3+ Fix from $2,3002026-03-27 MEDIUM 5.3 CVE-2026-0394 When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowe… Dovecot 2.4.0 / 3.1.0+ Fix from $1,6002026-03-27 CRITICAL 9.8 CVE-2026-33747 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when … Buildkit 0.28.1+ Fix from $2,3002026-03-27 CRITICAL 9.6 CVE-2026-33945 Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container… Incus 6.23.0+ Fix from $2,3002026-03-27 HIGH 8.8 CVE-2026-33686 Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil… Sharp 9.20.0+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-33670 SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file … Siyuan 3.6.2+ Fix from $1,9502026-03-26 HIGH 8.1 CVE-2026-33645 Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked uplo… Fireshare Mitigation only Fix from $1,9502026-03-26 MEDIUM 6.3 CVE-2026-0964 A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could… Hardened Images 0.11.4+ Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-33529 Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the conf… Zoraxy 3.3.2+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33528 GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API endpoint at `/api/v1/file/conten… Godoxy 0.27.5+ Fix from $1,6002026-03-26