Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2025-69612 A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download Template" func… Tms Management Console after 6.3.7.27386.20250818 Fix from $1,6002026-01-22 MEDIUM 6.0 CVE-2025-69820 Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via the joinCleanPath function. Beta9 No fix yet Fix from $1,6002026-01-22 HIGH 7.2 CVE-2025-67684 Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to u… Quick.cart Mitigation only Fix from $1,9502026-01-22 MEDIUM 5.5 CVE-2026-24049 wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vu… Wheel 0.46.2+ Fix from $1,6002026-01-22 HIGH 7.1 CVE-2026-24046 Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlin… Patch available Fix from $1,9502026-01-21 HIGH 7.5 CVE-2021-47849 Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information … Mini Mouse No fix yet Fix from $1,9502026-01-21 HIGH 7.5 CVE-2021-47850 Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafte… Mini Mouse No fix yet Fix from $1,9502026-01-21 HIGH 8.6 CVE-2026-23949 jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerabilit… Jaraco.context 6.1.0+ Fix from $1,9502026-01-20 MEDIUM 6.5 CVE-2026-22218EPSS 9% Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a… Chainlit 2.9.4+ Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-23850 SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering whi… Siyuan 3.5.4+ Fix from $1,9502026-01-19 MEDIUM 6.5 CVE-2026-23851 SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. Th… Siyuan 3.5.4+ Fix from $1,6002026-01-19 HIGH 7.5 CVE-2025-29847 A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if… Linkis 1.8.0+ Fix from $1,9502026-01-19 HIGH 7.5 CVE-2026-23644 esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software h… Esm.sh 136+ Fix from $1,9502026-01-18 HIGH 7.2 CVE-2026-1111 A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/T… Publiccms after 5.202506.d Fix from $1,9502026-01-18 MEDIUM 6.5 CVE-2025-13725 The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to arbitrary file reads in all ver… Mitigation only Fix from $1,6002026-01-17 MEDIUM 5.9 CVE-2025-12002 The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp… Mitigation only Fix from $1,6002026-01-17 MEDIUM 6.1 CVE-2026-23745 node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preser… Tar 7.5.3+ Fix from $1,6002026-01-16 HIGH 8.0 CVE-2026-23535 wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location w… Wlc 1.17.2+ Fix from $1,9502026-01-16 HIGH 7.8 CVE-2025-68921 SteelSeries Nahimic 3 1.10.7 allows Directory traversal. Nahimic 1.10.4+ Fix from $1,9502026-01-16 MEDIUM 6.5 CVE-2026-22876 Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vulnerability is exploited, arb… Mitigation only Fix from $1,6002026-01-16 MEDIUM 6.2 CVE-2021-47795 GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution throug… No fix yet Fix from $1,6002026-01-16 CRITICAL 9.8 CVE-2026-22249 Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write … Docmost 0.24.0+ Fix from $2,3002026-01-15 HIGH 8.1 CVE-2025-66292 DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/commo… Dpanel 1.9.2+ Fix from $1,9502026-01-15 HIGH 7.5 CVE-2025-67076 Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc… Agora Project 25.10+ Fix from $1,9502026-01-15 HIGH 7.5 CVE-2021-47755 Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsani… Oliver V5 Library 8.00.008.053+ Fix from $1,9502026-01-15 MEDIUM 5.3 CVE-2025-67083 Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read f… Invoiceplane 1.6.4+ Fix from $1,6002026-01-15 HIGH 7.5 CVE-2025-9142 A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory. Mitigation only Fix from $1,9502026-01-14 MEDIUM 6.5 CVE-2025-15020 The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.5.0 via the 'ghostban… Mitigation only Fix from $1,6002026-01-14 CRITICAL 9.8 CVE-2025-14301 The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is d… Mitigation only Fix from $2,3002026-01-14 HIGH 7.2 CVE-2022-50939 e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro… E107 No fix yet Fix from $1,9502026-01-13