Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.2 CVE-2026-25951 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an a… Fuxa 1.2.11+ Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-25895EPSS 10% FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at… Fuxa 1.2.10+ Fix from $2,3002026-02-09 HIGH 7.5 CVE-2026-22905 An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/… Mitigation only Fix from $1,9502026-02-09 MEDIUM 5.5 CVE-2025-15491 The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate paths passed to include func… Mitigation only Fix from $1,6002026-02-07 MEDIUM 6.5 CVE-2026-25760 Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem l… Sliver 1.6.11+ Fix from $1,6002026-02-06 HIGH 7.5 CVE-2026-25732 NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitiza… Nicegui 3.7.0+ Fix from $1,9502026-02-06 HIGH 8.6 CVE-2026-25635 calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere… Calibre 9.2.0+ Fix from $1,9502026-02-06 HIGH 7.8 CVE-2026-25636 calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corru… Calibre 9.2.0+ Fix from $1,9502026-02-06 CRITICAL 9.9 CVE-2026-25592 Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerab… Patch available Fix from $2,3002026-02-06 MEDIUM 5.4 CVE-2026-25640 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal v… Pydantic Ai 1.51.0+ Fix from $1,6002026-02-06 HIGH 8.1 CVE-2026-24135 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of … Gogs 0.13.4+ Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-23633 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook edi… Gogs 0.13.4+ Fix from $1,6002026-02-06 MEDIUM 5.5 CVE-2025-69619 A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. My Teditor No fix yet Fix from $1,6002026-02-05 HIGH 8.7 CVE-2026-1523 Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vulnerability allows an attacker … Mitigation only Fix from $1,9502026-02-05 HIGH 7.2 CVE-2026-25539 SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allow… Siyuan after 3.5.3 Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-25575 NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in t… Navigatum 2026-02-03+ Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-25499 Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudo… Terraform Provider 0.93.1+ Fix from $1,9502026-02-04 MEDIUM 6.5 CVE-2026-25475 OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths includ… Openclaw 2026.1.30+ Fix from $1,6002026-02-04 MEDIUM 5.5 CVE-2026-25145 melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange… Melange 0.40.5+ Fix from $1,6002026-02-04 HIGH 8.8 CVE-2026-25161 Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path trav… Alist 3.57.0+ Fix from $1,9502026-02-04 HIGH 8.4 CVE-2026-24843 melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar str… Melange 0.40.5+ Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-25121 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerabil… Apko 1.1.1+ Fix from $1,9502026-02-04 CRITICAL 9.8 CVE-2025-64712 The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a… Unstructured 0.18.18+ Fix from $2,3002026-02-04 HIGH 8.1 CVE-2026-25055 n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to … N8n 1.123.12 / 2.4.0f+ Fix from $1,9502026-02-04 MEDIUM 6.5 CVE-2025-69618 An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical interna… Coto No fix yet Fix from $1,6002026-02-04 MEDIUM 6.0 CVE-2026-20982 Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege. Android Mitigation only Fix from $1,6002026-02-04 MEDIUM 5.5 CVE-2026-20986 Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members. Members 15.5.05.4+ Fix from $1,6002026-02-04 HIGH 8.1 CVE-2025-69621 An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to overwrite critical internal fil… Mitigation only Fix from $1,9502026-02-04 MEDIUM 5.0 CVE-2025-69620 A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. Office Reader No fix yet Fix from $1,6002026-02-04 CRITICAL 9.8 CVE-2026-1812 A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/so… Bolo Solo after 2.6.4 Fix from $2,3002026-02-03