Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2026-7658 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass… Langflow 1.11.0+ Fix from $1,6002026-08-05 MEDIUM 5.4 CVE-2026-7869 IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs becaus… Langflow 1.11.0+ Fix from $1,6002026-08-05 HIGH 7.7 CVE-2026-8183 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10… Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7646 IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the… Langflow 1.11.0+ Fix from $1,6002026-08-05 CRITICAL 9.3 CVE-2026-9195 A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an… No fix yet Fix from $2,3002026-08-05 HIGH 8.1 CVE-2026-15979 The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in v… No fix yet Fix from $1,9502026-08-05 HIGH 8.0 CVE-2026-71279 Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT message (topic zigbee2mqtt/bridge/… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.9 CVE-2026-71268 OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes t… No fix yet Fix from $2,3002026-08-05 HIGH 7.2 CVE-2026-71269 Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-red/runtime/lib/storage/local… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-46581 In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a… Mojarra after 4.1.13 Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-61891 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/… Theia 1.74.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-60009 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen… Theia 1.74.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-12609 In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e… Theia 1.74.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requ… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, reso… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.8 CVE-2026-55747 The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonica… No fix yet Fix from $1,6002026-08-05 CRITICAL 10.0 CVE-2026-16940 The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete… No fix yet Fix from $2,3002026-08-05 MEDIUM 5.3 CVE-2026-18853 A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the componen… No fix yet Fix from $1,6002026-08-05 MEDIUM 5.5 CVE-2026-70592 Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the fil… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.6 CVE-2026-70593 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside … No fix yet Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-47682 CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write acce… No fix yet Fix from $1,9502026-08-04 HIGH 8.4 CVE-2026-47764 pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through… No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-47487 NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to,… Triton Inference Server Fix unknown Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-47612 NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a re… Dynamo after 1.0.0 Fix from $1,9502026-08-04 CRITICAL 9.0 CVE-2026-58072 A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. No fix yet Fix from $2,3002026-08-04 CRITICAL 9.1 CVE-2026-69110 OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files wit… No fix yet Fix from $2,3002026-08-04 HIGH 7.5 CVE-2026-67200 Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesy… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-14194 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMAN… No fix yet Fix from $1,6002026-08-04 HIGH 7.2 CVE-2026-14818 A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 … No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-56845 An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By includin… No fix yet Fix from $1,9502026-08-04