Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.0 CVE-2026-16955 The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an externa… No fix yet Fix from $1,6002026-08-08 CRITICAL 9.2 CVE-2026-47243 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-50540 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P… No fix yet Fix from $2,3002026-08-07 HIGH 8.7 CVE-2026-47659 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 HIGH 8.7 CVE-2026-47661 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 MEDIUM 6.3 CVE-2026-71557 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before be… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.9 CVE-2026-62996 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's … No fix yet Fix from $1,6002026-08-07 MEDIUM 6.9 CVE-2026-62992 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the … No fix yet Fix from $1,6002026-08-07 CRITICAL 9.8 CVE-2026-19264 Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload di… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.2 CVE-2026-66914 Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download file… No fix yet Fix from $2,3002026-08-07 HIGH 8.2 CVE-2026-66491 Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an … No fix yet Fix from $1,9502026-08-07 MEDIUM 6.1 CVE-2026-66492 Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action le… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.4 CVE-2026-66493 Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move ac… No fix yet Fix from $1,6002026-08-07 HIGH 8.8 CVE-2026-16263 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-contr… No fix yet Fix from $1,9502026-08-07 HIGH 8.8 CVE-2026-49163 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev… Application Insights Profiler No fix yet Fix from $1,9502026-08-07 HIGH 8.7 CVE-2026-71476 Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache ex… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.9 CVE-2026-64677 Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requeste… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.1 CVE-2026-64653 GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent … No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-61632 PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vul… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-19054 A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/re… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-18427 @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent dire… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.1 CVE-2026-53976 OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unau… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.5 CVE-2026-28146 Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19038 A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file s… No fix yet Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-18991 A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.9 CVE-2026-71313 rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local b… No fix yet Fix from $1,6002026-08-05 MEDIUM 5.4 CVE-2026-18959 A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopac… No fix yet Fix from $1,6002026-08-05 HIGH 8.6 CVE-2026-71309 rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve … No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-18953 Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 m… Aws Transform Mcp Server 0.1.5+ Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-17556 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire… Enterprise Server No fix yet Fix from $2,3002026-08-05