Vulnerability index

Browse CVEs

49 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11720

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL bui…

Fix: 1.3.0+
Fix from $2,300 2026-06-29
Chrome Devtools Mcp MEDIUM 6.1
CVE-2026-53766

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContex…

Fix: 1.1.0+
Fix from $1,600 2026-06-24
Android MEDIUM 6.2
CVE-2026-0055

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du…

Mitigation only
Fix from $1,600 2026-06-01
Clasp HIGH 8.8
CVE-2026-4092

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script proje…

Fix: 3.2.0+
Fix from $1,950 2026-03-13
Android HIGH 8.4
CVE-2025-48636

In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could …

Mitigation only
Fix from $1,950 2026-03-02
Android HIGH 7.8
CVE-2025-48567

In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode…

Mitigation only
Fix from $1,950 2026-03-02
Web Designer HIGH 7.8
CVE-2026-3223

Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.

No fix yet
Fix from $1,950 2026-02-27
Android MEDIUM 5.5
CVE-2025-48550

In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead …

Patch available
Fix from $1,600 2025-09-04
Osv Scalibr MEDIUM 6.5
CVE-2025-5981

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for con…

Fix: 0.1.8+
Fix from $1,600 2025-06-18
Web Designer HIGH 8.8
CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…

Fix: 16.3.0.0407+
Fix from $1,950 2025-06-12
Chrome HIGH 8.1
CVE-2025-1915

Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who co…

Fix: 134.0.6998.35+
Fix from $1,950 2025-03-05
Safearchive HIGH 7.5
CVE-2024-10389

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Writ…

Fix: 2024-10-25+
Fix from $1,950 2024-11-04
Android HIGH 7.8
CVE-2024-47027

In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This coul…

Mitigation only
Fix from $1,950 2024-10-25
Android HIGH 7.8
CVE-2023-35670

In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path travers…

Patch available
Fix from $1,950 2023-09-11
Android MEDIUM 5.5
CVE-2023-21268

In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial…

Patch available
Fix from $1,600 2023-08-14
Android HIGH 7.8
CVE-2023-21093

In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traver…

Patch available
Fix from $1,950 2023-04-19
Android HIGH 7.8
CVE-2023-20943

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could …

Patch available
Fix from $1,950 2023-02-28
Android MEDIUM 6.7
CVE-2022-20505

In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv…

Patch available
Fix from $1,600 2022-12-16
Google Search HIGH 7.8
CVE-2022-29580

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symb…

Fix: 13.41+
Fix from $1,950 2022-12-13
Android MEDIUM 5.5
CVE-2022-20453

In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local deni…

Mitigation only
Fix from $1,600 2022-11-08
Android HIGH 7.8
CVE-2022-20395

In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privile…

Mitigation only
Fix from $1,950 2022-09-13
Android MEDIUM 5.5
CVE-2022-33715

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of …

Mitigation only
Fix from $1,600 2022-08-05
Chrome MEDIUM 6.5
CVE-2022-1128

Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to …

Fix: 100.0.4896.60+
Fix from $1,600 2022-07-23
Android HIGH 7.8
CVE-2022-20220

In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv…

Patch available
Fix from $1,950 2022-07-13
Android MEDIUM 5.5
CVE-2022-20101

In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional…

Mitigation only
Fix from $1,600 2022-05-03
Android HIGH 7.8
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…

Mitigation only
Fix from $1,950 2022-04-11
Android HIGH 7.8
CVE-2021-25511

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal…

Mitigation only
Fix from $1,950 2021-12-08
Android HIGH 8.0
CVE-2021-25485

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote so…

Mitigation only
Fix from $1,950 2021-10-06
Android MEDIUM 6.5
CVE-2021-25450

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socke…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25452

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent …

Mitigation only
Fix from $1,600 2021-09-09