Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Tms Management Console MEDIUM 6.5
CVE-2025-69612

A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download Template" func…

Fix: after 6.3.7.27386.20250818
Fix from $1,600 2026-01-22
Beta9 MEDIUM 6.0
CVE-2025-69820

Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via the joinCleanPath function.

No fix yet
Fix from $1,600 2026-01-22
Quick.cart HIGH 7.2
CVE-2025-67684

Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to u…

Mitigation only
Fix from $1,950 2026-01-22
Wheel MEDIUM 5.5
CVE-2026-24049

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vu…

Fix: 0.46.2+
Fix from $1,600 2026-01-22
Unclassified HIGH 7.1
CVE-2026-24046

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlin…

Patch available
Fix from $1,950 2026-01-21
Mini Mouse HIGH 7.5
CVE-2021-47849

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information …

No fix yet
Fix from $1,950 2026-01-21
Mini Mouse HIGH 7.5
CVE-2021-47850

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafte…

No fix yet
Fix from $1,950 2026-01-21
Jaraco.context HIGH 8.6
CVE-2026-23949

jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerabilit…

Fix: 6.1.0+
Fix from $1,950 2026-01-20
Chainlit MEDIUM 6.5
CVE-2026-22218EPSS 9%

Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a…

Fix: 2.9.4+
Fix from $1,600 2026-01-20
Siyuan HIGH 7.5
CVE-2026-23850

SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering whi…

Fix: 3.5.4+
Fix from $1,950 2026-01-19
Siyuan MEDIUM 6.5
CVE-2026-23851

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. Th…

Fix: 3.5.4+
Fix from $1,600 2026-01-19
Linkis HIGH 7.5
CVE-2025-29847

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if…

Fix: 1.8.0+
Fix from $1,950 2026-01-19
Esm.sh HIGH 7.5
CVE-2026-23644

esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software h…

Fix: 136+
Fix from $1,950 2026-01-18
Publiccms HIGH 7.2
CVE-2026-1111

A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/T…

Fix: after 5.202506.d
Fix from $1,950 2026-01-18
Unclassified MEDIUM 6.5
CVE-2025-13725

The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to arbitrary file reads in all ver…

Mitigation only
Fix from $1,600 2026-01-17
Unclassified MEDIUM 5.9
CVE-2025-12002

The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.6.0 via the 'sby_check_wp…

Mitigation only
Fix from $1,600 2026-01-17
Tar MEDIUM 6.1
CVE-2026-23745

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preser…

Fix: 7.5.3+
Fix from $1,600 2026-01-16
Wlc HIGH 8.0
CVE-2026-23535

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location w…

Fix: 1.17.2+
Fix from $1,950 2026-01-16
Nahimic HIGH 7.8
CVE-2025-68921

SteelSeries Nahimic 3 1.10.7 allows Directory traversal.

Fix: 1.10.4+
Fix from $1,950 2026-01-16
Unclassified MEDIUM 6.5
CVE-2026-22876

Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vulnerability is exploited, arb…

Mitigation only
Fix from $1,600 2026-01-16
Unclassified MEDIUM 6.2
CVE-2021-47795

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution throug…

No fix yet
Fix from $1,600 2026-01-16
Docmost CRITICAL 9.8
CVE-2026-22249

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write …

Fix: 0.24.0+
Fix from $2,300 2026-01-15
Dpanel HIGH 8.1
CVE-2025-66292

DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/commo…

Fix: 1.9.2+
Fix from $1,950 2026-01-15
Agora Project HIGH 7.5
CVE-2025-67076

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc…

Fix: 25.10+
Fix from $1,950 2026-01-15
Oliver V5 Library HIGH 7.5
CVE-2021-47755

Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsani…

Fix: 8.00.008.053+
Fix from $1,950 2026-01-15
Invoiceplane MEDIUM 5.3
CVE-2025-67083

Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read f…

Fix: 1.6.4+
Fix from $1,600 2026-01-15
Unclassified HIGH 7.5
CVE-2025-9142

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.

Mitigation only
Fix from $1,950 2026-01-14
Unclassified MEDIUM 6.5
CVE-2025-15020

The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.5.0 via the 'ghostban…

Mitigation only
Fix from $1,600 2026-01-14
Unclassified CRITICAL 9.8
CVE-2025-14301

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is d…

Mitigation only
Fix from $2,300 2026-01-14
E107 HIGH 7.2
CVE-2022-50939

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro…

No fix yet
Fix from $1,950 2026-01-13