Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Rmm HIGH 7.5
CVE-2025-34395

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthentica…

Fix: 2025.1.1+
Fix from $1,950 2025-12-10
Gogs HIGH 8.8
CVE-2025-8110 KEVEPSS 83%

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Fix: after 0.13.3
Fix from $1,950 2025-12-10
Unclassified HIGH 7.5
CVE-2025-13339

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the templa…

Mitigation only
Fix from $1,950 2025-12-10
Pipeshub CRITICAL 9.8
CVE-2025-67506

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/…

Patch available
Fix from $2,300 2025-12-10
Coldfusion CRITICAL 9.1
CVE-2025-61811

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code…

Mitigation only
Fix from $2,300 2025-12-10
Nicegui HIGH 7.5
CVE-2025-66645

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, w…

Fix: 3.4.0+
Fix from $1,950 2025-12-09
Siyuan HIGH 8.8
CVE-2025-67488

SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function impo…

Fix: 3.5.0+
Fix from $1,950 2025-12-09
Minidvblinux HIGH 7.5
CVE-2023-53772

MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET para…

Fix: after 5.4
Fix from $1,950 2025-12-09
Provision MEDIUM 6.5
CVE-2021-47724

STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files…

No fix yet
Fix from $1,600 2025-12-09
Omen Gaming Hub HIGH 8.8
CVE-2025-11531

HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential …

Fix: 3.2.12 / 1101.2511.101.0+
Fix from $1,950 2025-12-09
Fortivoice HIGH 8.8
CVE-2025-60024

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoic…

Fix: 7.0.8 / 7.2.3+
Fix from $1,950 2025-12-09
Unclassified MEDIUM 6.8
CVE-2025-14311

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects JMRI: before 5.13.3.

Patch available
Fix from $1,600 2025-12-09
Robocode CRITICAL 9.1
CVE-2025-14306

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly …

Patch available
Fix from $2,300 2025-12-09
Endpoint Manager HIGH 8.0
CVE-2025-13661

Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of th…

Fix: 2024+
Fix from $1,950 2025-12-09
Unclassified MEDIUM 6.6
CVE-2025-13070

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include f…

Mitigation only
Fix from $1,600 2025-12-09
Dm2 Firmware CRITICAL 9.8
CVE-2025-14224

A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the componen…

Fix: after 1.9.12
Fix from $2,300 2025-12-08
Media Convergence System CRITICAL 9.8
CVE-2025-14182

A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the file /sobey-mchEditor/waterm…

Mitigation only
Fix from $2,300 2025-12-07
10web Booster HIGH 8.1
CVE-2025-13377

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to i…

Fix: 2.32.11+
Fix from $1,950 2025-12-06
Rar HIGH 8.1
CVE-2025-14111

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarla…

Fix: after 7.11
Fix from $1,950 2025-12-05
Warehouse Management System HIGH 8.1
CVE-2025-65879

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-contr…

Fix: after 1.2
Fix from $1,950 2025-12-05
Warehouse Management System HIGH 7.5
CVE-2025-65878

The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize use…

No fix yet
Fix from $1,950 2025-12-05
Zdh Web HIGH 8.8
CVE-2025-65897

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file up…

Fix: after 5.6.17
Fix from $1,950 2025-12-05
X210 Firmware HIGH 8.3
CVE-2025-64057

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locatio…

No fix yet
Fix from $1,950 2025-12-05
Ckfinder MEDIUM 6.5
CVE-2016-20023

In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provid…

Fix: 2.5.0.1+
Fix from $1,600 2025-12-05
Beedrive HIGH 7.8
CVE-2025-54160

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.…

Fix: 1.4.2-13960+
Fix from $1,950 2025-12-04
Torrent Suite Software HIGH 8.8
CVE-2025-54307

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupd…

Mitigation only
Fix from $1,950 2025-12-04
Laravel File Manager CRITICAL 9.1
CVE-2025-65346

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive con…

Fix: after 3.3.1
Fix from $2,300 2025-12-04
Router Manager MEDIUM 5.4
CVE-2025-29843

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

Fix: 1.3.1-9346+
Fix from $1,600 2025-12-04
Router Manager HIGH 7.2
CVE-2025-29846

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

Fix: 1.3.1-9346+
Fix from $1,950 2025-12-04
Laravel File Manager MEDIUM 6.5
CVE-2025-65345

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create arc…

Fix: after 3.3.1
Fix from $1,600 2025-12-03