Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-32846 OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path va… Openclaw after 2026.3.23 Fix from $1,9502026-03-26 HIGH 8.1 CVE-2025-41368 Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended re… Small Http Server 3.06.38+ Fix from $1,9502026-03-26 CRITICAL 9.1 CVE-2026-33183 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file path… Saloon 4.0.0+ Fix from $2,3002026-03-26 HIGH 8.8 CVE-2026-4758 The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfie… Mitigation only Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-30976 Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potential… Sonarr 4.0.17.2950+ Fix from $1,9502026-03-25 HIGH 7.5 CVE-2025-70952 pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow … Pf4j 3.14.1+ Fix from $1,9502026-03-25 HIGH 8.8 CVE-2025-67030 Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e001… Plexus Utils 3.6.1 / 4.0.3+ Fix from $1,9502026-03-25 MEDIUM 6.8 CVE-2026-32567 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in icopydoc YML for Yandex Market yml-for-yandex-market … Mitigation only Fix from $1,6002026-03-25 HIGH 8.6 CVE-2026-32522 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerc… Mitigation only Fix from $1,9502026-03-25 MEDIUM 6.8 CVE-2026-32496 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-… Mitigation only Fix from $1,6002026-03-25 HIGH 8.6 CVE-2026-31913 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.Thi… Mitigation only Fix from $1,9502026-03-25 HIGH 8.8 CVE-2026-27040 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issu… Mitigation only Fix from $1,9502026-03-25 MEDIUM 6.8 CVE-2026-25328 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce produ… Mitigation only Fix from $1,6002026-03-25 HIGH 7.7 CVE-2026-24969 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Trave… Mitigation only Fix from $1,9502026-03-25 HIGH 7.7 CVE-2026-24970 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.… Mitigation only Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-22448 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.3 CVE-2026-28827 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS So… macOS 14.8.5 / 15.7.5+ Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-20688 A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.… Ipados 14.8.5 / 15.7.5+ Fix from $2,3002026-03-25 HIGH 8.1 CVE-2026-33329 FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Res… Filerise 3.10.0+ Fix from $1,9502026-03-24 HIGH 8.1 CVE-2026-33344 Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDA… Dagu 2.3.1+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33497EPSS 20% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of th… Langflow 1.7.1+ Fix from $1,9502026-03-24 CRITICAL 9.9 CVE-2026-33309EPSS 11% Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6… Langflow 1.9.0+ Fix from $2,3002026-03-24 HIGH 8.6 CVE-2026-4741 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app/src/main/java/com/rdapps/gam… Patch available Fix from $1,9502026-03-24 HIGH 8.6 CVE-2026-22739 Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native … Mitigation only Fix from $1,9502026-03-24 CRITICAL 9.6 CVE-2026-33211 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3… Tekton Pipelines 1.3.3 / 1.6.1+ Fix from $2,3002026-03-24 HIGH 7.5 CVE-2026-33242 Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy compon… Salvo 0.89.3+ Fix from $1,9502026-03-24 CRITICAL 9.8 CVE-2026-33195 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's … Rails 7.2.3.1 / 8.0.4.1+ Fix from $2,3002026-03-24 HIGH 8.8 CVE-2026-33046 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to … Indico 3.3.12+ Fix from $1,9502026-03-23 HIGH 8.8 CVE-2025-60946 Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. Csweb Patch available Fix from $1,9502026-03-23 MEDIUM 6.5 CVE-2026-23481 Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditio… Blinko 1.8.4+ Fix from $1,6002026-03-23