Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Convertx HIGH 8.8
CVE-2025-66449

ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary f…

Fix: 0.16.0+
Fix from $1,950 2025-12-16
Freshrss HIGH 8.8
CVE-2025-58173

FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration par…

Fix: 1.27.1+
Fix from $1,950 2025-12-16
Icescrum HIGH 8.8
CVE-2025-60786

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a c…

Fix: after 7.54
Fix from $1,950 2025-12-15
Unclassified HIGH 8.7
CVE-2025-34181

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacke…

Mitigation only
Fix from $1,950 2025-12-15
N3 Firmware CRITICAL 9.8
CVE-2025-14704EPSS 12%

A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The m…

Fix: after 2.0.25
Fix from $2,300 2025-12-15
Unclassified MEDIUM 5.3
CVE-2025-14699

A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp…

Mitigation only
Fix from $1,600 2025-12-15
Unclassified MEDIUM 5.3
CVE-2025-14617

A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown function of the component org.jw.…

Mitigation only
Fix from $1,600 2025-12-13
macOS MEDIUM 5.5
CVE-2025-43463

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3, macOS So…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43465

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.1. An app may b…

Fix: 26.1+
Fix from $1,600 2025-12-12
Weaviate HIGH 7.2
CVE-2025-67818

An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absol…

Fix: 1.33.4+
Fix from $1,950 2025-12-12
Unclassified MEDIUM 6.5
CVE-2025-12960

The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.1 via the `href` parameter i…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified MEDIUM 6.5
CVE-2025-13891

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. Thi…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified CRITICAL 9.8
CVE-2025-14344

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'p…

Mitigation only
Fix from $2,300 2025-12-12
Unclassified HIGH 8.8
CVE-2025-12824

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderb…

Mitigation only
Fix from $1,950 2025-12-12
Unclassified HIGH 8.7
CVE-2024-58310

APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manip…

No fix yet
Fix from $1,950 2025-12-11
Xbtitfm HIGH 7.5
CVE-2024-58312

xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL par…

No fix yet
Fix from $1,950 2025-12-11
Cpanel HIGH 8.8
CVE-2025-66429

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitra…

Fix: 126.0.37 / 130.0.16+
Fix from $1,950 2025-12-11
Unclassified MEDIUM 6.5
CVE-2025-14293

The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUpload…

Mitigation only
Fix from $1,600 2025-12-11
Teamcity HIGH 7.5
CVE-2025-67742

In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

Fix: 2025.11+
Fix from $1,950 2025-12-11
Hfly CRITICAL 9.1
CVE-2025-14520

A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/inde…

Fix: after 2016-05-11
Fix from $2,300 2025-12-11
Hfly HIGH 7.5
CVE-2025-14521

A security vulnerability has been detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected element is an unknown function…

Fix: after 2016-05-11
Fix from $1,950 2025-12-11
Unclassified MEDIUM 6.5
CVE-2025-67720

Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messa…

Patch available
Fix from $1,600 2025-12-11
Qihang Media Web Digital Signage CRITICAL 9.1
CVE-2020-36898

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers t…

No fix yet
Fix from $2,300 2025-12-10
I Media Server Digital Signage HIGH 7.5
CVE-2020-36893

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files …

No fix yet
Fix from $1,950 2025-12-10
Fusion Digital Signage HIGH 8.1
CVE-2020-36883

SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backu…

Fix: after 3.4.8
Fix from $1,950 2025-12-10
Fearlesscms HIGH 7.5
CVE-2025-56430

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-…

No fix yet
Fix from $1,950 2025-12-10
Fearlesscms HIGH 7.5
CVE-2025-56431

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-…

No fix yet
Fix from $1,950 2025-12-10
Office App Edit Word\, Pdf File MEDIUM 6.5
CVE-2025-65814

A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory trav…

No fix yet
Fix from $1,600 2025-12-10
Document Reader\ MEDIUM 6.5
CVE-2025-65815

A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory tr…

No fix yet
Fix from $1,600 2025-12-10
Datagear CRITICAL 9.1
CVE-2025-65792

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

No fix yet
Fix from $2,300 2025-12-10