Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Frappe HIGH 7.5
CVE-2025-68953

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path …

Fix: 14.99.6 / 15.88.1+
Fix from $1,950 2026-01-05
Jspdf HIGH 7.5
CVE-2025-68428

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js b…

Fix: 4.0.0+
Fix from $1,950 2026-01-05
Kyuubi HIGH 8.8
CVE-2025-66518

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and…

Fix: 1.10.3+
Fix from $1,950 2026-01-05
Javamall CRITICAL 9.1
CVE-2025-15449

A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the function delete of the file s…

No fix yet
Fix from $2,300 2026-01-05
Warehouse MEDIUM 6.5
CVE-2026-0571

A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function create…

Fix: after 2025-10-06
Fix from $1,600 2026-01-02
Unclassified CRITICAL 9.2
CVE-2026-21440

AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write…

Patch available
Fix from $2,300 2026-01-02
Pa4 Firmware HIGH 7.5
CVE-2025-67160

An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal.

No fix yet
Fix from $1,950 2026-01-02
Qfiling HIGH 7.5
CVE-2025-59384

A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of u…

Mitigation only
Fix from $1,950 2026-01-02
Carrental HIGH 7.5
CVE-2025-15432

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability affects the function downloadSh…

Fix: after 2023-04-15
Fix from $1,950 2026-01-02
Impact Firmware HIGH 7.5
CVE-2022-50792

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access …

No fix yet
Fix from $1,950 2025-12-30
Impact Firmware CRITICAL 9.8
CVE-2022-50796

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path tr…

Mitigation only
Fix from $2,300 2025-12-30
Nixseparatedebuginfod HIGH 7.5
CVE-2025-61557

nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.

Fix: 0.4.1+
Fix from $1,950 2025-12-30
Vvvebjs HIGH 7.5
CVE-2024-25183

givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

No fix yet
Fix from $1,950 2025-12-29
Nagios Xi HIGH 7.5
CVE-2025-67254

NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

Mitigation only
Fix from $1,950 2025-12-29
Velociraptor MEDIUM 6.8
CVE-2025-14728

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is …

Fix: 0.75.6+
Fix from $1,600 2025-12-29
Greencms MEDIUM 6.5
CVE-2025-15187

A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Pe…

Fix: after 2.3
Fix from $1,600 2025-12-29
Bpmflowwebkit HIGH 7.5
CVE-2025-15227

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute…

Fix: 5.0.5+
Fix from $1,950 2025-12-29
Wmpro HIGH 7.5
CVE-2025-15225

WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to r…

Fix: after 5.2
Fix from $1,950 2025-12-29
Unclassified MEDIUM 6.2
CVE-2025-15066

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Travers…

Mitigation only
Fix from $1,600 2025-12-29
Tiny File Manager HIGH 7.2
CVE-2025-15138

A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php.…

Fix: after 2.6
Fix from $1,950 2025-12-28
Croogo MEDIUM 6.5
CVE-2024-42718

A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' pa…

No fix yet
Fix from $1,600 2025-12-26
Ch22 Firmware HIGH 7.3
CVE-2025-15076

A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path…

No fix yet
Fix from $1,950 2025-12-25
Netman 208 HIGH 7.2
CVE-2025-68916

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

Fix: 1.12+
Fix from $1,950 2025-12-24
Unclassified MEDIUM 6.5
CVE-2019-25256

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary sys…

No fix yet
Fix from $1,600 2025-12-24
Logicaldoc HIGH 7.5
CVE-2019-25258

LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files throug…

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 8.8
CVE-2019-25246EPSS 18%

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files v…

No fix yet
Fix from $1,950 2025-12-24
Ipn4g Firmware HIGH 8.4
CVE-2018-25144

Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attacke…

No fix yet
Fix from $1,950 2025-12-24
Pdf Architect HIGH 7.8
CVE-2025-14420

pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $1,950 2025-12-23
Soda Pdf Desktop HIGH 7.8
CVE-2025-14413

Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-23
Unclassified HIGH 7.0
CVE-2025-13699

MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2025-12-23