Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-28807 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows arbitrary file read via percen… Wisp 2.2.1+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-30952 liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render, and include tags allow arbi… Liquidjs 10.25.0+ Fix from $1,9502026-03-10 HIGH 8.0 CVE-2026-27825 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_downloa… Mcp Atlassian 0.17.0+ Fix from $1,9502026-03-10 MEDIUM 6.5 CVE-2026-30973 Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Prior to 7.0.6, @appium/support … Appium\/support 7.0.6+ Fix from $1,6002026-03-10 MEDIUM 6.5 CVE-2026-30942 Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an authenticated path traversal … Flare 1.7.3+ Fix from $1,6002026-03-10 HIGH 8.6 CVE-2026-30958 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:compo… Oneuptime 10.0.21+ Fix from $1,9502026-03-10 MEDIUM 6.8 CVE-2026-2741 Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, … Vaadin 14.14.1 / 23.6.7+ Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2026-23907 This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFil… Pdfbox after 3.0.7 Fix from $1,6002026-03-10 HIGH 7.5 CVE-2025-54659 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Co… Fortisoar Agent Communication Bridge Mitigation only Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-3585 The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_impor… Mitigation only Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2026-30869 SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read … Siyuan 3.5.10+ Fix from $2,3002026-03-10 MEDIUM 5.5 CVE-2026-31802 node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extrac… Tar 7.5.11+ Fix from $1,6002026-03-10 MEDIUM 6.5 CVE-2026-1776 Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation th… Camaleon Cms after 2.9.0 Fix from $1,6002026-03-10 HIGH 8.1 CVE-2026-30240 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in th… Budibase after 3.31.5 Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-70028 An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-… Sunbirded Portal Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2026-0846 A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation … Nltk No fix yet Fix from $1,9502026-03-09 MEDIUM 6.5 CVE-2026-3089 Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation o… Actual 26.3.0+ Fix from $1,6002026-03-09 MEDIUM 6.5 CVE-2025-41755 A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a param… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,6002026-03-09 HIGH 8.8 CVE-2025-41757 A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not val… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 HIGH 8.8 CVE-2025-41758 A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead … Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2026-3795 A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v… Doracms Mitigation only Fix from $2,3002026-03-09 MEDIUM 5.3 CVE-2026-3719 A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the f… Mitigation only Fix from $1,6002026-03-08 MEDIUM 6.5 CVE-2026-3695 A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipula… Modern Image Gallery App No fix yet Fix from $1,6002026-03-08 MEDIUM 5.5 CVE-2026-29780 eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Pri… Eml Parser 2.0.1+ Fix from $1,6002026-03-07 MEDIUM 6.3 CVE-2026-29786 node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction … Tar 7.5.10+ Fix from $1,6002026-03-07 MEDIUM 5.3 CVE-2026-29190 Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Traversal vulnerability in the b… Karapace 6.0.0+ Fix from $1,6002026-03-07 HIGH 7.2 CVE-2025-14675 The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' functio… Patch available Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-30828 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system… Wallos 4.6.2+ Fix from $1,9502026-03-07 MEDIUM 5.3 CVE-2026-29790 dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnera… Dbt Common 1.34.2 / 1.37.3+ Fix from $1,6002026-03-06 HIGH 8.2 CVE-2026-29064 Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive ext… Zarf 0.73.1+ Fix from $1,9502026-03-06