Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.3
CVE-2025-64485

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1, a malicious CVAT user with …

Patch available
Fix from $1,600 2025-11-08
Kubevirt MEDIUM 6.5
CVE-2025-64433

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arb…

Fix: 1.5.3+
Fix from $1,600 2025-11-07
Tquadra Cms HIGH 7.5
CVE-2025-60574

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to prope…

No fix yet
Fix from $1,950 2025-11-07
Astrbot HIGH 7.5
CVE-2025-57698

AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-up…

No fix yet
Fix from $1,950 2025-11-07
Unclassified MEDIUM 5.3
CVE-2025-7719

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File M…

Mitigation only
Fix from $1,600 2025-11-07
Qsync Central MEDIUM 6.5
CVE-2025-57712

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.3+
Fix from $1,600 2025-11-07
Unclassified MEDIUM 6.0
CVE-2025-64346

archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to feed a specially crafted archiv…

Patch available
Fix from $1,600 2025-11-07
Unclassified HIGH 8.8
CVE-2025-64184

Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from di…

Patch available
Fix from $1,950 2025-11-07
Deviceon\/iedge HIGH 8.8
CVE-2025-58423

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse di…

Fix: after 2.0.2
Fix from $1,950 2025-11-06
Deviceon\/iedge CRITICAL 9.8
CVE-2025-59171

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code exe…

Fix: after 2.0.2
Fix from $2,300 2025-11-06
Deviceon\/iedge CRITICAL 9.8
CVE-2025-62630

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code exe…

Fix: after 2.0.2
Fix from $2,300 2025-11-06
Webaccess\/vpn MEDIUM 6.5
CVE-2025-34238

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConf…

Fix: 1.1.5+
Fix from $1,600 2025-11-06
Unclassified HIGH 8.8
CVE-2025-12490EPSS 20%

Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files …

Patch available
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60242

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Anatoly Download Counter download-counter allows Path…

Mitigation only
Fix from $1,950 2025-11-06
Cursor HIGH 8.8
CVE-2025-64107

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects p…

Fix: 2.0+
Fix from $1,950 2025-11-04
Cursor HIGH 8.8
CVE-2025-64108

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci…

Fix: 2.0+
Fix from $1,950 2025-11-04
Shoplentor CRITICAL 9.8
CVE-2025-12493

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera…

Fix: 3.2.6+
Fix from $2,300 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43382

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.2, macOS So…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Nextchat HIGH 7.5
CVE-2025-50735

Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-al…

Fix: after 2.16.0
Fix from $1,950 2025-11-03
Unclassified HIGH 8.6
CVE-2025-10897

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it pos…

Mitigation only
Fix from $1,950 2025-10-31
Unclassified MEDIUM 6.8
CVE-2025-8385

The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input valid…

Mitigation only
Fix from $1,600 2025-10-31
Tivoli Monitoring HIGH 7.5
CVE-2025-3355

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $1,950 2025-10-30
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3356

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $2,300 2025-10-30
Unclassified HIGH 8.9
CVE-2025-12060

The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility…

Patch available
Fix from $1,950 2025-10-30
Mlflow CRITICAL 9.8
CVE-2025-11201EPSS 27%

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …

Fix: 2025-06-10+
Fix from $2,300 2025-10-29
Blu Ic2 Firmware CRITICAL 9.8
CVE-2025-12422

Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; B…

Fix: 1.20+
Fix from $2,300 2025-10-28
Unclassified HIGH 8.9
CVE-2025-62725EPSS 14%

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends…

Patch available
Fix from $1,950 2025-10-27
Trufusion Enterprise HIGH 8.6
CVE-2025-27222

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't proper…

Fix: after 7.10.4.0
Fix from $1,950 2025-10-27
Unclassified HIGH 7.5
CVE-2025-12055

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 8.1
CVE-2025-10488

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to i…

Mitigation only
Fix from $1,950 2025-10-25