Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.8 CVE-2026-32709 PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVL… Px4 Drone Autopilot 1.17.0+ Fix from $1,6002026-03-16 MEDIUM 6.4 CVE-2026-32719 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th… Anythingllm after 1.11.1 Fix from $1,6002026-03-16 HIGH 7.5 CVE-2026-2493 IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive info… Mitigation only Fix from $1,9502026-03-16 MEDIUM 5.5 CVE-2026-21000 Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. Galaxy Store 4.6.03.8+ Fix from $1,6002026-03-16 MEDIUM 5.5 CVE-2026-21001 Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. Galaxy Store 4.6.03.8+ Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2026-21005 Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege. Smart Switch 3.7.69.15+ Fix from $1,6002026-03-16 HIGH 8.8 CVE-2026-4092 Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script proje… Clasp 3.2.0+ Fix from $1,9502026-03-13 HIGH 7.6 CVE-2026-31886 Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoin… Dagu 2.2.4+ Fix from $1,9502026-03-13 HIGH 8.2 CVE-2026-30853 calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability i… Calibre 9.5.0+ Fix from $1,9502026-03-13 HIGH 8.1 CVE-2026-30914 SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protoc… Sftpgo 2.7.1+ Fix from $1,9502026-03-13 MEDIUM 5.4 CVE-2026-23942 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. … Erlang\/otp 5.1.4.14 / 5.2.11.6+ Fix from $1,6002026-03-13 HIGH 7.5 CVE-2026-22199 Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenti… Wpdiscuz 7.6.47+ Fix from $1,9502026-03-13 MEDIUM 6.3 CVE-2025-66249 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.… Livy 0.9.0+ Fix from $1,6002026-03-13 HIGH 7.5 CVE-2026-32274 Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of whi… Black 26.3.1+ Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2026-32232 ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink A… Zeptoclaw after 0.7.5 Fix from $2,3002026-03-12 HIGH 8.8 CVE-2026-32140 Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC d… Dataease 2.10.20+ Fix from $1,9502026-03-12 HIGH 8.1 CVE-2026-32116 Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a… Magic Wormhole 0.23.0+ Fix from $1,9502026-03-12 HIGH 7.4 CVE-2026-28791 Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload … Tinacms\/cli 2.1.7+ Fix from $1,9502026-03-12 CRITICAL 9.6 CVE-2026-28792 Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al… Tinacms\/cli 2.1.8+ Fix from $2,3002026-03-12 HIGH 8.4 CVE-2026-28793 Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path … Tinacms\/cli 2.1.8+ Fix from $1,9502026-03-12 MEDIUM 6.3 CVE-2026-24125 Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative fil… Tinacms\/graphql 2.1.2+ Fix from $1,6002026-03-12 MEDIUM 6.5 CVE-2026-3954 A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application… Mitigation only Fix from $1,6002026-03-11 HIGH 7.5 CVE-2019-25480 ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulati… No fix yet Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2019-25471 FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the… File Thingie after 2.5.7 Fix from $2,3002026-03-11 MEDIUM 6.5 CVE-2026-30234 OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions ca… Openproject 17.2.0+ Fix from $1,6002026-03-11 HIGH 7.1 CVE-2026-27897 Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py wi… Vociferous 4.4.2+ Fix from $1,9502026-03-11 HIGH 8.7 CVE-2026-3013 Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vuln… Mitigation only Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-32060 OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the… Openclaw 2026.2.14+ Fix from $1,9502026-03-11 MEDIUM 6.8 CVE-2026-21360 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pat… Commerce 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 HIGH 8.5 CVE-2026-31817 OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists … Olivetin 3000.11.2+ Fix from $1,9502026-03-10