Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Esm.sh CRITICAL 9.8
CVE-2025-65025

esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path trav…

Fix: 136+
Fix from $2,300 2025-11-19
Astro MEDIUM 5.3
CVE-2025-64765

Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the app…

Fix: 5.15.8+
Fix from $1,600 2025-11-19
Agent Dvr HIGH 7.8
CVE-2025-63408

Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive…

Fix: after 6.6.7.0
Fix from $1,950 2025-11-18
Ewio2 M Firmware HIGH 8.8
CVE-2025-41736

A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resu…

Fix: 2.2.0+
Fix from $1,950 2025-11-18
Serv U CRITICAL 9.1
CVE-2025-40549

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability t…

Fix: 15.5.3+
Fix from $2,300 2025-11-18
Pdfpatcher MEDIUM 6.2
CVE-2025-63918

PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files t…

Fix: 1.1.3.4663+
Fix from $1,600 2025-11-17
Unclassified MEDIUM 5.3
CVE-2025-13266

A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the file vlife-base/src/main/java/…

Mitigation only
Fix from $1,600 2025-11-17
Lsfusion Platform CRITICAL 9.1
CVE-2025-13265

A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/ls…

Fix: after 6.1
Fix from $2,300 2025-11-17
Lsfusion Platform CRITICAL 9.8
CVE-2025-13262

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file pl…

Fix: after 6.1
Fix from $2,300 2025-11-17
Lsfusion Platform MEDIUM 5.3
CVE-2025-13261

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/ls…

Fix: after 6.1
Fix from $1,600 2025-11-17
Unclassified MEDIUM 6.3
CVE-2025-13246

A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthe…

Mitigation only
Fix from $1,600 2025-11-16
Backitup HIGH 8.6
CVE-2025-63680

Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fall…

Fix: after 2025
Fix from $1,950 2025-11-14
Vios CRITICAL 9.1
CVE-2025-36236

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse …

Mitigation only
Fix from $2,300 2025-11-13
Unclassified MEDIUM 6.5
CVE-2025-12089

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the …

Mitigation only
Fix from $1,600 2025-11-13
Unclassified HIGH 8.7
CVE-2022-4982

DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes han…

No fix yet
Fix from $1,950 2025-11-12
Unclassified HIGH 8.7
CVE-2023-7327

Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation allows an unauthenticated att…

No fix yet
Fix from $1,950 2025-11-12
Unclassified HIGH 8.7
CVE-2016-15055

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the …

No fix yet
Fix from $1,950 2025-11-12
Unclassified HIGH 8.7
CVE-2021-4463

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' e…

No fix yet
Fix from $1,950 2025-11-12
N Central CRITICAL 9.8
CVE-2025-11366

N-central < 2025.4 is vulnerable to authentication bypass via path traversal

Fix: 2025.4+
Fix from $2,300 2025-11-12
Unclassified HIGH 7.3
CVE-2025-11565

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated system access w…

Mitigation only
Fix from $1,950 2025-11-12
Firewall Analyzer HIGH 8.8
CVE-2025-12382

Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to uploa…

Mitigation only
Fix from $1,950 2025-11-12
Github Copilot Chat MEDIUM 6.8
CVE-2025-62449

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized atta…

Fix: 0.32.0+
Fix from $1,600 2025-11-11
Onedrive MEDIUM 6.5
CVE-2025-60722

Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privi…

Fix: 7.42+
Fix from $1,600 2025-11-11
Unclassified HIGH 8.9
CVE-2025-11696

A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any…

Mitigation only
Fix from $1,950 2025-11-11
Business Connector MEDIUM 6.8
CVE-2025-42894

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-42919

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated UR…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified HIGH 8.7
CVE-2018-25124

PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer comp…

No fix yet
Fix from $1,950 2025-11-10
Openclinica HIGH 8.8
CVE-2025-12922

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm …

Mitigation only
Fix from $1,950 2025-11-10
Unclassified MEDIUM 6.5
CVE-2025-12092

The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality …

Patch available
Fix from $1,600 2025-11-08
Unclassified MEDIUM 6.5
CVE-2025-12000

The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() functi…

Mitigation only
Fix from $1,600 2025-11-08