Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Command Center Rx HIGH 7.5
CVE-2022-50932

Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system …

No fix yet
Fix from $1,950 2026-01-13
Owlfiles HIGH 7.5
CVE-2022-50890

Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. …

No fix yet
Fix from $1,950 2026-01-13
Rich Text Editor HIGH 7.5
CVE-2021-47751

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows …

Fix: after 6.6
Fix from $1,950 2026-01-13
Youphptube MEDIUM 5.5
CVE-2021-47749

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the '…

Fix: after 7.8
Fix from $1,600 2026-01-13
Guarddog CRITICAL 9.8
CVE-2026-22871

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract…

Fix: 2.7.1+
Fix from $2,300 2026-01-13
Archibus HIGH 7.5
CVE-2025-25652

In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversa…

No fix yet
Fix from $1,950 2026-01-13
Fortivoice MEDIUM 6.5
CVE-2025-58693

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoic…

Fix: 7.0.8 / 7.2.3+
Fix from $1,600 2026-01-13
Manageengine Admanager Plus MEDIUM 5.5
CVE-2025-9435

Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

Fix: 7.2+
Fix from $1,600 2026-01-13
Gin Vue Admin HIGH 7.2
CVE-2026-22786

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint res…

Fix: after 2.8.7
Fix from $1,950 2026-01-12
Pal Mcp Server MEDIUM 6.5
CVE-2025-66689

A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The v…

Fix: 9.8.2+
Fix from $1,600 2026-01-12
Mindsdb CRITICAL 9.1
CVE-2025-68472EPSS 20%

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the f…

Fix: 25.11.1+
Fix from $2,300 2026-01-12
Dx Netops Spectrum MEDIUM 6.5
CVE-2025-69267

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Pa…

Fix: 24.3.9+
Fix from $1,600 2026-01-12
Devtoys CRITICAL 9.8
CVE-2026-22685

DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension i…

Fix: 2.0.9.0+
Fix from $2,300 2026-01-10
React Router\/node CRITICAL 9.1
CVE-2025-61686EPSS 16%

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node …

Fix: 2.17.2 / 7.9.4+
Fix from $2,300 2026-01-10
Couchcms MEDIUM 6.5
CVE-2025-67004EPSS 6%

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back af…

No fix yet
Fix from $1,600 2026-01-09
Unclassified HIGH 7.5
CVE-2025-66744

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing una…

Mitigation only
Fix from $1,950 2026-01-09
Ip7137 Firmware MEDIUM 6.5
CVE-2025-66051

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources b…

Mitigation only
Fix from $1,600 2026-01-09
Wget2 CRITICAL 9.8
CVE-2025-69194

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Meta…

Fix: 2.2.1+
Fix from $2,300 2026-01-09
Unclassified MEDIUM 6.5
CVE-2019-25295

The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. Th…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 6.2
CVE-2017-20212EPSS 8%

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to rea…

No fix yet
Fix from $1,600 2026-01-08
Monai MEDIUM 5.3
CVE-2026-21851

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a Path Traversal (Zip Slip) vuln…

Fix: after 1.5.1
Fix from $1,600 2026-01-07
Redaxo MEDIUM 6.5
CVE-2026-21857

REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within…

Fix: 5.20.2+
Fix from $1,600 2026-01-07
Rustfs CRITICAL 9.8
CVE-2025-68705EPSS 7%

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerabi…

Patch available
Fix from $2,300 2026-01-07
Css HIGH 7.5
CVE-2026-0669

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows…

Patch available
Fix from $1,950 2026-01-07
Unclassified MEDIUM 6.5
CVE-2025-14867

The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'source' attribute of the 'flash…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified HIGH 7.5
CVE-2025-13801

The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via the file parameter. This makes…

Mitigation only
Fix from $1,950 2026-01-07
Snapgear Sg560 Firmware HIGH 8.8
CVE-2020-36909

SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files u…

No fix yet
Fix from $1,950 2026-01-06
Unclassified HIGH 8.8
CVE-2025-14997

The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in …

Mitigation only
Fix from $1,950 2026-01-06
Unclassified MEDIUM 6.5
CVE-2026-0604

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7…

Mitigation only
Fix from $1,600 2026-01-06
Aiohttp MEDIUM 5.3
CVE-2025-69226

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existen…

Fix: 3.13.3+
Fix from $1,600 2026-01-05