Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2026-1793 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the… Mitigation only Fix from $1,6002026-02-15 HIGH 8.1 CVE-2026-26187 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/… Lakefs 1.77.0+ Fix from $1,9502026-02-13 HIGH 7.5 CVE-2026-21878 BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet… Bacnet Stack Patch available Fix from $1,9502026-02-13 CRITICAL 10.0 CVE-2025-69770 A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via upl… Mitigation only Fix from $2,3002026-02-13 HIGH 7.5 CVE-2019-25333 Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipu… No fix yet Fix from $1,9502026-02-12 HIGH 7.5 CVE-2026-26217 Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /… Crawl4ai 0.8.0+ Fix from $1,9502026-02-12 HIGH 7.5 CVE-2025-15577 An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA We… Dna after 2022 Fix from $1,9502026-02-12 MEDIUM 5.5 CVE-2026-20669 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may b… macOS 26.3+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2026-20653 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, … Ipados 14.8.4 / 15.7.4+ Fix from $1,6002026-02-11 HIGH 7.5 CVE-2026-20660 A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, … Safari 14.8.4 / 18.7.5+ Fix from $1,9502026-02-11 HIGH 7.8 CVE-2026-20615 A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.… Ipados 14.8.4 / 26.3+ Fix from $1,9502026-02-11 MEDIUM 5.5 CVE-2026-20625 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS So… macOS 14.8.4 / 15.7.4+ Fix from $1,6002026-02-11 HIGH 7.8 CVE-2026-20614 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An … macOS 14.8.4 / 15.7.4+ Fix from $1,9502026-02-11 MEDIUM 5.3 CVE-2025-64074 A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete ar… Mitigation only Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-43417 A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app m… macOS 14.8.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-43537 A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restorin… Ipados 18.7.5+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2026-25062 Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from… Outline 1.4.0+ Fix from $1,6002026-02-11 HIGH 7.5 CVE-2020-37214 Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path para… No fix yet Fix from $1,9502026-02-11 HIGH 7.5 CVE-2025-70084 Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted … Opensatkit Mitigation only Fix from $1,9502026-02-11 CRITICAL 9.8 CVE-2025-69874 nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outsi… Nanotar after 0.2.0 Fix from $2,3002026-02-11 HIGH 7.5 CVE-2026-25869 MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-control… Minigal Nano after 0.3.5 Fix from $1,9502026-02-11 CRITICAL 10.0 CVE-2025-64075 A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass au… Mitigation only Fix from $2,3002026-02-11 MEDIUM 6.5 CVE-2025-66278 A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulne… File Station 5.5.6.5190+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2025-68406 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2026-22894 A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulne… File Station 5.5.6.5190+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2025-62853 A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulne… File Station 5.5.6.5190+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2025-58470 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.3 CVE-2026-25872 JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The a… Mitigation only Fix from $1,6002026-02-10 HIGH 7.5 CVE-2026-25992 SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block … Siyuan 3.5.5+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-0651 A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET request… Tapo C260 Firmware 1.1.9+ Fix from $1,9502026-02-10