Vulnerability index

Browse CVEs

8,862 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-6540 Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re… Calico 3.21.7 / 3.22.4+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-15435 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-14519 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a … App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-59310 KEV VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i… Vcenter Server No fix yet Fix from $2,3002026-07-30 MEDIUM 5.3 CVE-2026-16531 An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-67247 A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not su… Data Master 5.1.4.rjv2+ Fix from $1,6002026-07-30 HIGH 8.1 CVE-2026-67245 A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is no… Data Master 5.1.4.rjv2+ Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-67246 A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is … Data Master 5.1.4.rjv2+ Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-5491 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-5492 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-5487 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-5489 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,6002026-07-29 CRITICAL 10.0 CVE-2026-67429 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller… Mitigation only Fix from $2,3002026-07-29 MEDIUM 6.5 CVE-2026-13723 A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by expl… No fix yet Fix from $1,6002026-07-29 MEDIUM 5.9 CVE-2026-50558 Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in p… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-65886 Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view … Gridbox 2.20.2+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-65889 Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet… Gridbox 2.20.2+ Fix from $1,9502026-07-29 MEDIUM 6.9 CVE-2026-44943 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create… No fix yet Fix from $1,6002026-07-29 HIGH 8.6 CVE-2026-11974 The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two A… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-66063 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler s… No fix yet Fix from $1,6002026-07-28 MEDIUM 6.9 CVE-2026-54659 Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver… No fix yet Fix from $1,6002026-07-28 HIGH 8.6 CVE-2026-54650 openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.P… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55389 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.62.0+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55390 datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_gen… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-15280 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i… Websphere Application Server 26.0.0.9+ Fix from $1,9502026-07-28 CRITICAL 9.3 CVE-2026-14973 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. Aspera after 1.0.19 Fix from $2,3002026-07-28 HIGH 7.8 CVE-2026-48374 Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary fi… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-67185 TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequenc… No fix yet Fix from $1,9502026-07-28 HIGH 7.1 CVE-2026-54545 wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once … No fix yet Fix from $1,9502026-07-28