Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.9 CVE-2026-24848EPSS 6% OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() … Openemr 7.0.4+ Fix from $2,3002026-03-03 MEDIUM 6.5 CVE-2026-2606 IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to … Webmethods Api Gateway Mitigation only Fix from $1,6002026-03-03 HIGH 7.8 CVE-2026-28518 OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attac… Openviking 0.2.1+ Fix from $1,9502026-03-03 HIGH 8.8 CVE-2026-2448 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate… Mitigation only Fix from $1,9502026-03-03 HIGH 8.4 CVE-2025-48636 In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could … Android Mitigation only Fix from $1,9502026-03-02 HIGH 7.8 CVE-2025-48567 In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode… Android Mitigation only Fix from $1,9502026-03-02 HIGH 8.0 CVE-2026-0655 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authentic… Deco Be25 Firmware after 1.1.1 Fix from $1,9502026-03-02 HIGH 8.1 CVE-2026-3405 A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The… Jeesite after 5.15.1 Fix from $1,9502026-03-02 HIGH 7.5 CVE-2026-28414 Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vul… Gradio 6.7.0+ Fix from $1,9502026-02-27 HIGH 8.2 CVE-2026-28406 kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to versi… Kaniko 1.25.10+ Fix from $1,9502026-02-27 MEDIUM 6.5 CVE-2026-27734 Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/b… Beszel 0.18.2+ Fix from $1,6002026-02-27 MEDIUM 6.5 CVE-2026-24488 OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an ar… Openemr after 8.0.0 Fix from $1,6002026-02-27 HIGH 8.8 CVE-2026-2749 Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on… Open Tickets 24.04.7 / 24.10.8+ Fix from $1,9502026-02-27 HIGH 7.8 CVE-2026-3223 Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer. Web Designer No fix yet Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-21659 Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2251 Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal … Freeflow Core 8.1.0+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-3289 A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the… Publiccms Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-22877 An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the… Xweb 300d Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 MEDIUM 5.9 CVE-2026-28208EPSS 12% Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows … Junrar 7.5.8+ Fix from $1,6002026-02-26 HIGH 7.5 CVE-2026-23939 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module)… Hexpm 2026-02-26+ Fix from $1,9502026-02-26 CRITICAL 9.8 CVE-2025-50857 ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code v… Mitigation only Fix from $2,3002026-02-26 HIGH 8.8 CVE-2026-1311 The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functio… Mitigation only Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-27969 Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac… Vitess 22.0.4 / 23.0.3+ Fix from $1,9502026-02-26 HIGH 7.5 CVE-2026-1557 The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This… Mitigation only Fix from $1,9502026-02-26 MEDIUM 5.3 CVE-2026-27884 NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file and folder path when saving fi… Patch available Fix from $1,6002026-02-26 MEDIUM 6.5 CVE-2026-27735 Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to… Model Context Protocol Servers 2026.1.14+ Fix from $1,6002026-02-26 HIGH 7.4 CVE-2026-27800 Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. … Zed 0.224.4+ Fix from $1,9502026-02-26 HIGH 7.2 CVE-2026-27819 Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restor… Vikunja 2.0.0+ Fix from $1,9502026-02-25 HIGH 8.8 CVE-2026-26984 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris 26.0.5 / 27.0.2+ Fix from $1,9502026-02-25 MEDIUM 6.5 CVE-2026-26985 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris 26.0.5 / 27.0.2+ Fix from $1,6002026-02-25