Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.7 CVE-2025-68862 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File Dropzone woo-file-dropzone a… Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.5 CVE-2025-68002 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map open-user-map allows Path Tr… Mitigation only Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2025-59819 This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an internal system path. Mitigation only Fix from $1,6002026-02-20 HIGH 8.8 CVE-2026-26065 calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path … Calibre 9.3.0+ Fix from $1,9502026-02-20 HIGH 7.1 CVE-2026-26960 node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hard… Tar 7.5.8+ Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-26064 calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversa… Calibre 9.3.0+ Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-26975 Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow un… Music Assistant Server 2.7.0+ Fix from $1,9502026-02-20 MEDIUM 6.7 CVE-2026-26972 OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. … Openclaw 2026.2.13+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26329 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying … Openclaw 2026.2.14+ Fix from $1,6002026-02-20 HIGH 7.5 CVE-2026-26321 OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2025-8054 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal.  The vulnera… Xm Fax Mitigation only Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-26202 Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from … Penpot 2.13.2+ Fix from $1,9502026-02-19 MEDIUM 5.3 CVE-2026-25766 Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal… Echo 5.0.3+ Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25527 changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts … Changedetection 0.53.2+ Fix from $1,6002026-02-19 CRITICAL 10.0 CVE-2026-2731 Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers t… Mitigation only Fix from $2,3002026-02-19 MEDIUM 6.5 CVE-2026-2692 A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component… Cyreneadmin after 1.3.0 Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-2672 A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function… Electronic Archives System after 3.2.210802 Fix from $1,6002026-02-18 HIGH 7.5 CVE-2019-25352 Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL pa… No fix yet Fix from $1,9502026-02-18 HIGH 7.5 CVE-2019-25355 gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path travers… Gsoap No fix yet Fix from $1,9502026-02-18 HIGH 7.5 CVE-2026-23491 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get… Invoiceplane 1.6.4+ Fix from $1,9502026-02-18 HIGH 7.5 CVE-2026-22860 Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match o… Rack 2.2.22 / 3.1.20+ Fix from $1,9502026-02-18 MEDIUM 5.7 CVE-2026-20137 In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2… Splunk 9.2.9 / 9.3.7+ Fix from $1,6002026-02-18 HIGH 8.7 CVE-2026-2464 Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read arbitrary files from the unde… Mitigation only Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2026-2426 The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in th… Patch available Fix from $1,6002026-02-18 HIGH 8.8 CVE-2026-2623 A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/common-iaas/src/main/java/com/b… Blossom after 1.17.1 Fix from $1,9502026-02-17 MEDIUM 6.5 CVE-2026-22762 Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitation of a Pathname to a Restrict… Mitigation only Fix from $1,6002026-02-17 MEDIUM 6.5 CVE-2025-36598 Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vu… Mitigation only Fix from $1,6002026-02-17 HIGH 8.8 CVE-2025-12062 The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion i… Mitigation only Fix from $1,9502026-02-17 MEDIUM 5.5 CVE-2026-2552 A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component … Zentao after 21.7.8 Fix from $1,6002026-02-16 MEDIUM 5.4 CVE-2026-2551 A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the co… Zentao after 21.7.8 Fix from $1,6002026-02-16