Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.4 CVE-2026-18645 A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the co… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-18646 A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component A… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-18648 A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFile… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-18644 A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the compo… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-69153 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19,… Postcss 8.5.23+ Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-61372 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F… Jena Fuseki 6.2.0+ Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-69095 OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-69089 Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Tool… No fix yet Fix from $1,9502026-08-03 HIGH 7.7 CVE-2026-69086 SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to constr… No fix yet Fix from $1,9502026-08-03 HIGH 7.1 CVE-2026-9856 A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue r… No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-9335 A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalL… No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-13339 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_c… No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-18352 The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' p… No fix yet Fix from $1,9502026-08-02 HIGH 7.8 CVE-2026-67309 Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (… No fix yet Fix from $1,9502026-08-01 MEDIUM 6.3 CVE-2026-67295 FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths … No fix yet Fix from $1,6002026-08-01 HIGH 8.1 CVE-2026-15450 The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and … No fix yet Fix from $1,9502026-08-01 HIGH 7.2 CVE-2026-15244 The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before concatenating it into a file inc… No fix yet Fix from $1,9502026-08-01 MEDIUM 5.3 CVE-2026-15932 The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthentica… No fix yet Fix from $1,6002026-08-01 HIGH 7.5 CVE-2026-15006 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal… No fix yet Fix from $1,9502026-08-01 MEDIUM 6.2 CVE-2026-54785 gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-62999 Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path… No fix yet Fix from $1,9502026-07-31 HIGH 8.7 CVE-2026-53502 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boun… No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-62391 The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-… Kyuubi 1.12.0+ Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-44615 Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not… Zeppelin 0.12.1+ Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-63222 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filena… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-56673 ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and … No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-56671 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py jo… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-66755 Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker… Tika 3.3.2+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-12942 IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted… Langflow 1.10.2+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-62663 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, doc… No fix yet Fix from $1,9502026-07-30