Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Modula Image Gallery HIGH 7.2
CVE-2025-13645

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_fi…

Fix: 2.13.3+
Fix from $1,950 2025-12-03
Unclassified MEDIUM 6.3
CVE-2025-13875

A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocih…

Mitigation only
Fix from $1,600 2025-12-02
Hd Video Player All Formats HIGH 7.8
CVE-2025-13876

A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the co…

No fix yet
Fix from $1,950 2025-12-02
Gin Vue Admin CRITICAL 9.1
CVE-2025-66410

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causi…

Fix: after 2.8.6
Fix from $2,300 2025-12-01
Grav HIGH 8.5
CVE-2025-66300

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav MEDIUM 6.8
CVE-2025-66302

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated att…

Fix: 1.8.0+
Fix from $1,600 2025-12-01
Grav HIGH 8.8
CVE-2025-66295

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and su…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Frappe HIGH 8.6
CVE-2025-66206

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein s…

Fix: 14.99.2 / 15.86.0+
Fix from $1,950 2025-12-01
Publiccms HIGH 7.5
CVE-2025-65838

PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

No fix yet
Fix from $1,950 2025-12-01
Epub File Reader HIGH 7.1
CVE-2025-63365

SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file processing component, specifically …

Mitigation only
Fix from $1,950 2025-12-01
Mogublog HIGH 8.8
CVE-2025-13816

A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file…

Fix: after 5.2
Fix from $1,950 2025-12-01
Webstack Guns HIGH 7.5
CVE-2025-13810

A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java/com/jsnjfz/manage/modular/sy…

No fix yet
Fix from $1,950 2025-12-01
Scada Lts MEDIUM 6.5
CVE-2025-13791

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProje…

Fix: after 2.7.8.1
Fix from $1,600 2025-11-30
Unclassified HIGH 8.0
CVE-2025-12638

Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerabi…

Mitigation only
Fix from $1,950 2025-11-28
Unclassified HIGH 7.3
CVE-2025-59890

Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an atta…

Mitigation only
Fix from $1,950 2025-11-27
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66262

Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.1
CVE-2025-66251

Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30…

No fix yet
Fix from $2,300 2025-11-26
Unclassified HIGH 8.7
CVE-2025-65952

Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability e…

Patch available
Fix from $1,950 2025-11-25
Unclassified HIGH 8.7
CVE-2025-34350

UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoi…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified MEDIUM 6.9
CVE-2025-59372

A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to wri…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified CRITICAL 9.2
CVE-2025-59366EPSS 16%

An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality…

Mitigation only
Fix from $2,300 2025-11-25
Unclassified HIGH 8.2
CVE-2025-12003

A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device.…

Mitigation only
Fix from $1,950 2025-11-25
Pingalert Application Server CRITICAL 9.9
CVE-2025-54347

A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attack…

Fix: 6.1.1.6+
Fix from $2,300 2025-11-24
Openatlas HIGH 8.1
CVE-2025-60915

An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a pat…

Fix: after 8.12.0
Fix from $1,950 2025-11-24
Fluent Bit MEDIUM 5.3
CVE-2025-12972

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses un…

Mitigation only
Fix from $1,600 2025-11-24
macOS MEDIUM 5.5
CVE-2025-31248

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sono…

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-11-21
Unclassified CRITICAL 9.3
CVE-2025-34320

BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allow…

Mitigation only
Fix from $2,300 2025-11-20
Resty HIGH 8.1
CVE-2025-13435

A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/sr…

Fix: after 1.3.1
Fix from $1,950 2025-11-20
7 Zip HIGH 7.8
CVE-2025-11001EPSS 27%

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2025-11-19
Onecommander HIGH 7.5
CVE-2025-63371

Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specific…

Mitigation only
Fix from $1,950 2025-11-19