Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-27704 The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Fl… Dart Software Development Kit 3.11.0 / 3.41.0+ Fix from $1,9502026-02-25 CRITICAL 9.8 CVE-2026-27699 The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` m… Basic Ftp 5.2.0+ Fix from $2,3002026-02-25 CRITICAL 9.1 CVE-2026-0704 In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va… Octopus Server 2025.3.14715+ Fix from $2,3002026-02-25 HIGH 8.1 CVE-2026-3179 The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI… Data Master 5.1.2.reo1+ Fix from $1,9502026-02-25 CRITICAL 9.8 CVE-2026-25785 Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacke… Lanscope Endpoint Manager 9.4.8.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27641 Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remo… Flask Reuploaded 1.5.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27606 Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present i… Rollup 2.80.0 / 3.30.0+ Fix from $2,3002026-02-25 MEDIUM 6.5 CVE-2026-24849 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument… Openemr 7.0.4+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-27598 Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/… Dagu after 1.16.7 Fix from $1,6002026-02-25 HIGH 7.5 CVE-2026-27117 bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulne… Bit7z 4.0.11+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-25891 Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the sta… Fiber 3.1.0+ Fix from $1,9502026-02-24 MEDIUM 6.6 CVE-2026-25603 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents o… Mr9600 Firmware No fix yet Fix from $1,6002026-02-24 HIGH 8.8 CVE-2026-27483EPSS 11% MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability i… Mindsdb 25.9.1.1+ Fix from $1,9502026-02-24 HIGH 7.2 CVE-2025-15589 A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the … Muyucms No fix yet Fix from $1,9502026-02-24 HIGH 8.8 CVE-2026-3067 A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-co… Hummerrisk after 1.5.0 Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-25965 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $1,9502026-02-24 HIGH 7.6 CVE-2026-3051EPSS 6% A vulnerability has been found in DataLinkDC dinky up to 1.2.5. The affected element is the function getProjectDir of the file dinky-admin/src/main/j… Dinky after 1.2.5 Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2026-23521 Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or ed… Traccar after 6.11.1 Fix from $1,6002026-02-23 CRITICAL 9.1 CVE-2026-2953 A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o… Ujcms No fix yet Fix from $2,3002026-02-22 MEDIUM 5.4 CVE-2026-2864 A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the func… Mitigation only Fix from $1,6002026-02-21 MEDIUM 5.4 CVE-2026-2863 A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the fu… Mitigation only Fix from $1,6002026-02-21 HIGH 7.5 CVE-2026-27202 GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file … Getsimple Cms No fix yet Fix from $1,9502026-02-21 HIGH 7.3 CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut… Patch available Fix from $1,9502026-02-20 HIGH 7.1 CVE-2026-27115 ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigge… Adb Explorer 0.9.26021+ Fix from $1,9502026-02-20 HIGH 8.2 CVE-2026-2818 A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended ext… Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.5 CVE-2026-24953 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list all… Mitigation only Fix from $1,6002026-02-20 HIGH 8.6 CVE-2025-69376 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allow… Mitigation only Fix from $1,9502026-02-20 HIGH 7.7 CVE-2025-69377 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allow… Mitigation only Fix from $1,9502026-02-20 HIGH 8.6 CVE-2025-69379 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhe… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2025-69380 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhe… Mitigation only Fix from $1,9502026-02-20