Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.2 CVE-2018-25194 Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious co… No fix yet Fix from $1,9502026-03-06 HIGH 7.5 CVE-2018-25181 Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the par… No fix yet Fix from $1,9502026-03-06 MEDIUM 6.2 CVE-2018-25184 Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the … No fix yet Fix from $1,6002026-03-06 HIGH 7.5 CVE-2018-25178 Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating th… Easyndexer No fix yet Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-29059 Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticat… Windmill 1.603.3+ Fix from $1,9502026-03-06 CRITICAL 9.1 CVE-2026-29065 changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore func… Changedetection 0.54.4+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28795 OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through n… Openchatbi 0.2.2+ Fix from $2,3002026-03-06 HIGH 8.0 CVE-2026-28800 Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a… Natro Macro 1.1.0+ Fix from $1,9502026-03-06 HIGH 8.8 CVE-2026-28676 OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storag… Opensift 1.6.3+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-28679 Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a downl… Homegallery 1.21.0+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-28429 Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified in the gameName parameter. Whi… Talishar 2026-02-22+ Fix from $1,9502026-03-06 MEDIUM 6.7 CVE-2026-26124 '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. Aci Confidential Containers No fix yet Fix from $1,6002026-03-05 HIGH 7.1 CVE-2026-28482 OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing d… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 MEDIUM 5.5 CVE-2026-28486 OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allow… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 HIGH 7.9 CVE-2026-28457 OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmat… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 CRITICAL 9.1 CVE-2026-28462 OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and … Openclaw 2026.2.13+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28453 OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 MEDIUM 6.5 CVE-2026-28447 OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin packa… Openclaw 2026.2.1+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28393 OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-24457 An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's… Openmq after 6.5.1 Fix from $2,3002026-03-05 HIGH 7.5 CVE-2025-45691 An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems… Ragas after 0.2.14 Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2025-70231 D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin… Dir 513 Firmware Mitigation only Fix from $2,3002026-03-05 MEDIUM 5.5 CVE-2026-28538 Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos Mitigation only Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-2743 Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf… Seppmail after 15.0.2.1 Fix from $2,3002026-03-05 HIGH 8.6 CVE-2026-22460 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax FormGent formgent allows Path Traversal.This is… Mitigation only Fix from $1,9502026-03-05 HIGH 7.5 CVE-2025-69411 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-te… Mitigation only Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-28427 OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins… Opendeck 2.8.1+ Fix from $1,9502026-03-04 HIGH 7.5 CVE-2026-0847 A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including … Nltk after 3.9.2 Fix from $1,9502026-03-04 HIGH 7.5 CVE-2026-27442 The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, … Seppmail 15.0.1+ Fix from $1,9502026-03-04 MEDIUM 6.5 CVE-2026-28769 A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex … Sfx2100 Firmware No fix yet Fix from $1,6002026-03-04