Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.2
CVE-2025-68476

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been ide…

Patch available
Fix from $1,950 2025-12-22
Mybb HIGH 8.8
CVE-2023-53979

MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code…

No fix yet
Fix from $1,950 2025-12-22
Impact Firmware HIGH 7.5
CVE-2023-53962

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary file…

No fix yet
Fix from $1,950 2025-12-22
Np P502h Firmware HIGH 7.5
CVE-2025-11540

Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

Mitigation only
Fix from $1,950 2025-12-22
Unclassified MEDIUM 5.5
CVE-2025-14965

A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the function upload/delete of the f…

Mitigation only
Fix from $1,600 2025-12-19
Eve Ng HIGH 7.6
CVE-2025-67442

EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface la…

No fix yet
Fix from $1,950 2025-12-19
Tkfiles HIGH 7.5
CVE-2025-66905

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A rem…

No fix yet
Fix from $1,950 2025-12-19
Br 6208ac Firmware MEDIUM 6.5
CVE-2025-14910

A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation re…

No fix yet
Fix from $1,600 2025-12-19
Weblate CRITICAL 9.1
CVE-2025-68398

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i…

Fix: 5.15.1+
Fix from $2,300 2025-12-18
Weblate MEDIUM 6.5
CVE-2025-68279

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf…

Fix: 5.15.1+
Fix from $1,600 2025-12-18
Unclassified HIGH 8.7
CVE-2025-34452EPSS 5%

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vul…

Patch available
Fix from $1,950 2025-12-18
Webaccess\/scada HIGH 7.5
CVE-2025-67653

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Mitigation only
Fix from $1,950 2025-12-18
Webaccess\/scada CRITICAL 9.1
CVE-2025-14850

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

Mitigation only
Fix from $2,300 2025-12-18
Webserver MEDIUM 6.5
CVE-2023-53944

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root…

No fix yet
Fix from $1,600 2025-12-18
Unclassified MEDIUM 6.5
CVE-2025-64235

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue af…

Mitigation only
Fix from $1,600 2025-12-18
Cmc HIGH 8.1
CVE-2025-40898

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authe…

Fix: 25.5.0+
Fix from $1,950 2025-12-18
Unclassified HIGH 7.7
CVE-2025-64230

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-protection allows Path Traversal.T…

Mitigation only
Fix from $1,950 2025-12-18
Unclassified MEDIUM 6.5
CVE-2025-54748

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg allows Path Traversal.This is…

Mitigation only
Fix from $1,600 2025-12-18
Model Context Protocol Servers HIGH 8.8
CVE-2025-68143EPSS 8%

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…

Fix: 2025.9.25+
Fix from $1,950 2025-12-17
Model Context Protocol Servers CRITICAL 9.1
CVE-2025-68145EPSS 7%

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository…

Fix: 2025.12.18+
Fix from $2,300 2025-12-17
Bludit MEDIUM 6.5
CVE-2023-53907

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitra…

Fix: 3.13.1+
Fix from $1,600 2025-12-17
Ritecms HIGH 7.5
CVE-2025-67171

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

No fix yet
Fix from $1,950 2025-12-17
Ritecms HIGH 7.5
CVE-2025-67174

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the ad…

No fix yet
Fix from $1,950 2025-12-17
Nginx Ingress Controller HIGH 8.3
CVE-2025-14727

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached En…

Mitigation only
Fix from $1,950 2025-12-17
Unclassified HIGH 7.5
CVE-2025-68155

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@v…

Patch available
Fix from $1,950 2025-12-16
Allsky CRITICAL 10.0
CVE-2025-63414

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command exec…

Mitigation only
Fix from $2,300 2025-12-16
Websitebaker MEDIUM 6.5
CVE-2023-53902

WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating direct…

No fix yet
Fix from $1,600 2025-12-16
Video Management Software Server MEDIUM 6.5
CVE-2025-65075

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit…

Fix: after 6.42.4
Fix from $1,600 2025-12-16
Video Management Software Server MEDIUM 6.1
CVE-2025-65076

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit…

Fix: after 6.42.4
Fix from $1,600 2025-12-16
Video Management Software Server HIGH 7.2
CVE-2025-65074

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit…

Fix: after 6.42.4
Fix from $1,950 2025-12-16