Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2026-1056EPSS 12% The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_di… Mitigation only Fix from $2,3002026-01-28 HIGH 8.2 CVE-2026-24842 node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path res… Tar 7.5.7+ Fix from $1,9502026-01-28 HIGH 8.1 CVE-2026-24741 ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to c… Convertx 0.17.0+ Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2026-24770 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a … Ragflow after 0.23.1 Fix from $2,3002026-01-27 HIGH 7.5 CVE-2026-23593 A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view … Mitigation only Fix from $1,9502026-01-27 HIGH 7.5 CVE-2020-36939 Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path t… No fix yet Fix from $1,9502026-01-27 MEDIUM 6.9 CVE-2026-24801 Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source modules). This vulnerability is … Patch available Fix from $1,6002026-01-27 CRITICAL 9.8 CVE-2026-24479EPSS 8% HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduo… Hustoj 26.01.24+ Fix from $2,3002026-01-27 HIGH 7.5 CVE-2026-24486 Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default co… Python Multipart 0.0.22+ Fix from $1,9502026-01-27 HIGH 7.2 CVE-2026-24478 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, … Anythingllm 1.10.0+ Fix from $1,9502026-01-27 MEDIUM 6.5 CVE-2026-24123 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's `bentof… Bentoml 1.4.34+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-23888 pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files… Pnpm 10.28.1+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-23889 pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write f… Pnpm 10.28.1+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-24056 pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads the… Pnpm 10.28.2+ Fix from $1,6002026-01-26 MEDIUM 5.5 CVE-2026-24131 pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validatin… Pnpm 10.28.2+ Fix from $1,6002026-01-26 HIGH 7.5 CVE-2026-24469 C++ HTTP Server is an HTTP/1.1 server built to handle client connections and serve HTTP requests. Versions 1.0 and below are vulnerable to Path Trave… Mitigation only Fix from $1,9502026-01-24 HIGH 7.8 CVE-2025-11002 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code … 7 Zip Mitigation only Fix from $1,9502026-01-23 HIGH 7.8 CVE-2026-20613 The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an ar… Container 0.8.0 / 0.21.0+ Fix from $1,9502026-01-23 MEDIUM 5.8 CVE-2026-24137 sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/c… Patch available Fix from $1,6002026-01-23 CRITICAL 9.8 CVE-2026-21227 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… Azure Logic Apps Mitigation only Fix from $2,3002026-01-22 HIGH 8.7 CVE-2026-23954 Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom … Incus 6.21.0+ Fix from $1,9502026-01-22 HIGH 8.8 CVE-2025-66428 An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation. Mitigation only Fix from $1,9502026-01-22 HIGH 8.6 CVE-2025-69097 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.T… Mitigation only Fix from $1,9502026-01-22 MEDIUM 6.5 CVE-2025-69055 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Tr… Mitigation only Fix from $1,6002026-01-22 HIGH 8.6 CVE-2025-68912 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2025-68907 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 hostmev2 allows Path Traversal.… Mitigation only Fix from $1,9502026-01-22 HIGH 8.6 CVE-2025-68901 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This is… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2025-68902 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This is… Mitigation only Fix from $1,9502026-01-22 HIGH 8.6 CVE-2025-67963 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ovatheme Movie Booking movie-booking allows Path Trav… Mitigation only Fix from $1,9502026-01-22 HIGH 8.7 CVE-2023-7335 EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unau… Mitigation only Fix from $1,9502026-01-22