Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2026-73033 Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integri… No fix yet Fix from $4,0002026-08-10 HIGH 8.1 CVE-2026-72903 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal file… No fix yet Fix from $4,9002026-08-10 HIGH 7.1 CVE-2026-69112 Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.9 CVE-2026-12339 A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequ… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.3 CVE-2026-47754 Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta… No fix yet Fix from $5,7502026-08-10 MEDIUM 5.5 CVE-2026-15059 Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. No fix yet Fix from $4,0002026-08-10 CRITICAL 9.8 CVE-2026-72567 An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or … No fix yet Fix from $5,7502026-08-10 CRITICAL 9.1 CVE-2026-72569 A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside… No fix yet Fix from $5,7502026-08-10 HIGH 7.5 CVE-2026-72571 A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from t… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-72572 A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the… No fix yet Fix from $4,9002026-08-10 HIGH 7.2 CVE-2026-13170 The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing user… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.3 CVE-2026-19372 A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSy… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19371 A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the c… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19370 A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19366 A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the … No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19365 A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the compone… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19338 A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mc… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19336 A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/to… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19335 A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the fi… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.5 CVE-2026-18465 The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19331 A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/Ca… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19330 A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to … No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19327 A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enri… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19328 A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninst… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19325 A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This… No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19323 A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the … No fix yet Fix from $4,0002026-08-09 MEDIUM 5.3 CVE-2026-19288 A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of th… No fix yet Fix from $1,6002026-08-08 MEDIUM 5.3 CVE-2026-19287 A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This m… No fix yet Fix from $1,6002026-08-08 MEDIUM 5.3 CVE-2026-19285 A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function J… No fix yet Fix from $1,6002026-08-08 MEDIUM 5.3 CVE-2026-19270 A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_s… No fix yet Fix from $1,6002026-08-08