Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Digital Experience Platform HIGH 7.5
CVE-2025-62254

The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 th…

Fix: after 7.4.3.111
Fix from $1,950 2025-10-23
Socet Gxp MEDIUM 6.5
CVE-2025-54963

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafted job r…

Fix: 4.6.0.2+
Fix from $1,600 2025-10-23
Gandia Integra Total MEDIUM 6.5
CVE-2025-41073

Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file c…

Mitigation only
Fix from $1,600 2025-10-23
Wp Pipes HIGH 8.6
CVE-2025-60227

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.Thi…

Fix: after 1.4.3
Fix from $1,950 2025-10-22
Unclassified HIGH 7.7
CVE-2025-60217

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt-luxa-addons allows Path Trav…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.7
CVE-2025-59566

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows …

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.7
CVE-2025-58959

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Taskbot taskbot allows Path Traversal.This…

Mitigation only
Fix from $1,950 2025-10-22
Jira Data Center MEDIUM 6.5
CVE-2025-22167

This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Sof…

Fix: 9.12.28 / 10.3.12+
Fix from $1,600 2025-10-22
Unclassified MEDIUM 6.0
CVE-2025-62522

Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to …

Patch available
Fix from $1,600 2025-10-20
Unclassified HIGH 7.1
CVE-2025-3465

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB CoreSense™ M10.This issue affe…

Mitigation only
Fix from $1,950 2025-10-20
E107 HIGH 8.1
CVE-2025-11941

A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of t…

Fix: after 2.3.3
Fix from $1,950 2025-10-19
Churchcrm HIGH 7.2
CVE-2025-11939

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php …

Fix: after 5.18.0
Fix from $1,950 2025-10-19
Streamax Crocus HIGH 7.5
CVE-2025-11914

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceF…

No fix yet
Fix from $1,950 2025-10-17
Streamax Crocus MEDIUM 6.5
CVE-2025-11913

A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the …

No fix yet
Fix from $1,600 2025-10-17
Clipbucket MEDIUM 6.5
CVE-2025-62424

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vul…

Fix: 5.5.2-147+
Fix from $1,600 2025-10-17
Unclassified CRITICAL 9.8
CVE-2025-62353

A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of c…

Mitigation only
Fix from $2,300 2025-10-17
Unclassified HIGH 7.5
CVE-2025-62356

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of curren…

Mitigation only
Fix from $1,950 2025-10-17
Unclassified CRITICAL 9.3
CVE-2025-11849

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package…

Patch available
Fix from $2,300 2025-10-17
Eve X1 Server Firmware HIGH 7.5
CVE-2025-34517

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attack…

Fix: after 4.7.18.0
Fix from $1,950 2025-10-16
Eve X1 Server Firmware HIGH 7.5
CVE-2025-34518

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacke…

Fix: after 4.7.18.0
Fix from $1,950 2025-10-16
Unclassified MEDIUM 6.3
CVE-2025-11842

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handl…

Mitigation only
Fix from $1,600 2025-10-16
Fortidlp Agent HIGH 7.8
CVE-2025-53951

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy pl…

Fix: after 11.5.1
Fix from $1,950 2025-10-16
Fortidlp Agent HIGH 7.8
CVE-2025-54658

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy pl…

Fix: after 11.5.1
Fix from $1,950 2025-10-16
Unclassified HIGH 7.2
CVE-2025-61941

A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered by an administrative user who …

Mitigation only
Fix from $1,950 2025-10-15
Unclassified MEDIUM 5.5
CVE-2025-10406

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to incl…

Mitigation only
Fix from $1,600 2025-10-15
Unclassified HIGH 8.8
CVE-2025-11746

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popu…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified HIGH 8.7
CVE-2024-13991

Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to th…

Mitigation only
Fix from $1,950 2025-10-15
Argo Workflows HIGH 8.8
CVE-2025-62156

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and version…

Fix: 3.6.12 / 3.7.3+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile MEDIUM 5.5
CVE-2025-10986

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin pr…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,600 2025-10-14
Factorytalk View CRITICAL 9.1
CVE-2025-9064

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …

Fix: after 15.0
Fix from $2,300 2025-10-14