Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2026-32771 The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces).… Monitoring 0.2.2+ Fix from $2,3002026-03-20 MEDIUM 6.5 CVE-2026-32758 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6… Filebrowser 2.62.0+ Fix from $1,6002026-03-20 MEDIUM 5.9 CVE-2026-22737 Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of co… Spring Framework 5.3.47 / 6.1.26+ Fix from $1,6002026-03-20 MEDIUM 6.8 CVE-2026-32750 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly t… Siyuan 3.6.1+ Fix from $1,6002026-03-19 HIGH 8.2 CVE-2026-32036 OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authenticatio… Openclaw 2026.2.6+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-32030 OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths w… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32033 OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundar… Openclaw 2026.2.24+ Fix from $1,6002026-03-19 HIGH 8.6 CVE-2026-32026 OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 MEDIUM 5.5 CVE-2026-32020 OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-r… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 8.1 CVE-2026-32007 OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox a… Openclaw 2026.2.23+ Fix from $1,9502026-03-19 CRITICAL 9.1 CVE-2026-32749 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploa… Siyuan 3.6.1+ Fix from $2,3002026-03-19 MEDIUM 6.5 CVE-2026-25928 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export featu… Openemr 8.0.0.2+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2025-67115 A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows … Mitigation only Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-30403 There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can … Wgcloud after 3.6.3 Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-3029 A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5. Patch available Fix from $1,9502026-03-19 CRITICAL 10.0 CVE-2026-22557EPSS 28% A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t… Mitigation only Fix from $2,3002026-03-19 HIGH 7.5 CVE-2026-32805 Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with… Romeo 0.2.2+ Fix from $1,9502026-03-18 CRITICAL 9.9 CVE-2026-32731 ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `… Import Export 3.5.3+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2025-15031 A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,… Mlflow after 3.10.1 Fix from $2,3002026-03-18 HIGH 8.8 CVE-2026-33001 Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing… Jenkins 2.541.3 / 2.555+ Fix from $1,9502026-03-18 MEDIUM 5.5 CVE-2026-27522 OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxR… Openclaw 2026.2.24+ Fix from $1,6002026-03-18 HIGH 7.5 CVE-2026-27523 OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path check… Openclaw 2026.2.24+ Fix from $1,9502026-03-18 CRITICAL 9.1 CVE-2026-22171 OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol… Openclaw 2026.2.19+ Fix from $2,3002026-03-18 HIGH 7.5 CVE-2026-32981 A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and san… Ray 2.8.1+ Fix from $1,9502026-03-17 HIGH 7.2 CVE-2026-25770 Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, … Wazuh 4.14.3+ Fix from $1,9502026-03-17 MEDIUM 5.5 CVE-2026-21991 A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names. Linux Mitigation only Fix from $1,6002026-03-16 HIGH 8.7 CVE-2026-29522 ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoin… Mitigation only Fix from $1,9502026-03-16 HIGH 7.5 CVE-2025-66687 Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-3839 Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication… Unraid Mitigation only Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-3838 Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff… Unraid Mitigation only Fix from $1,9502026-03-16