Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2026-1811 A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/… Bolo Solo after 2.6.4 Fix from $1,9502026-02-03 MEDIUM 6.2 CVE-2020-37086 Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system… No fix yet Fix from $1,6002026-02-03 HIGH 7.5 CVE-2020-37088 School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'docume… School Erp Pro No fix yet Fix from $1,9502026-02-03 MEDIUM 6.5 CVE-2020-37077 Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators… No fix yet Fix from $1,6002026-02-03 MEDIUM 6.5 CVE-2026-24053 Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible … Claude Code 2.0.74+ Fix from $1,6002026-02-03 HIGH 8.8 CVE-2026-1810 A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org… Bolo Solo after 2.6.4 Fix from $1,9502026-02-03 HIGH 8.8 CVE-2025-65077 A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be… Mitigation only Fix from $1,9502026-02-03 MEDIUM 5.4 CVE-2025-61646 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. … Mediawiki 1.39.14 / 1.43.4+ Fix from $1,6002026-02-03 MEDIUM 6.1 CVE-2025-61641 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php. This issue a… Mediawiki 1.39.14 / 1.43.4+ Fix from $1,6002026-02-03 HIGH 8.8 CVE-2026-25059 OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability in multiple file operation h… Openlist 4.1.10+ Fix from $1,9502026-02-02 CRITICAL 9.8 CVE-2025-66480 Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re… Im Server 1.4.3+ Fix from $2,3002026-02-02 HIGH 7.6 CVE-2025-14914 IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal se… Websphere Application Server after 26.0.0.1 Fix from $1,9502026-02-02 HIGH 8.6 CVE-2026-1186 EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Leg… Mitigation only Fix from $1,9502026-02-02 MEDIUM 6.5 CVE-2022-50950 Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attack… Mitigation only Fix from $1,6002026-02-01 MEDIUM 6.5 CVE-2021-47921 Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipulate application path requests … Mitigation only Fix from $1,6002026-02-01 CRITICAL 9.3 CVE-2026-25069 SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauth… Mitigation only Fix from $2,3002026-02-01 HIGH 7.5 CVE-2020-37041 OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can read arbitrary files from th… Opencti No fix yet Fix from $1,9502026-01-30 HIGH 7.5 CVE-2020-37034 HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and fil… No fix yet Fix from $1,9502026-01-30 MEDIUM 6.5 CVE-2026-25152 Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDo… Backstage 1.13.11 / 1.14.1+ Fix from $1,6002026-01-30 HIGH 8.8 CVE-2026-0963 An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to p… Crafty Controller Mitigation only Fix from $1,9502026-01-30 HIGH 8.8 CVE-2026-0805 An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform f… Crafty Controller 4.8.0+ Fix from $1,9502026-01-30 HIGH 8.8 CVE-2026-25116 Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability … Runtipi 4.7.2+ Fix from $1,9502026-01-29 MEDIUM 5.0 CVE-2026-24846 malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8.0 and prior to version 1.20.… Malcontent 1.20.3+ Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2026-24687 Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authenticated backoffice-user to enu… Umbraco Forms 16.4.1 / 17.1.1+ Fix from $1,6002026-01-29 HIGH 7.5 CVE-2020-37015 The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access se… No fix yet Fix from $1,9502026-01-29 HIGH 7.5 CVE-2026-1616 The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack… Open Security Issue Management 2025.9.0+ Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-24897 Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… Erugo after 0.2.14 Fix from $1,9502026-01-28 MEDIUM 5.5 CVE-2026-1532 A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the compon… Dcs 700l Firmware after 1.03.09 Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-69601 A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are aut… 66biolinks No fix yet Fix from $1,6002026-01-28 HIGH 8.4 CVE-2020-36970 PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin… No fix yet Fix from $1,9502026-01-28