Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.3
CVE-2025-42906

SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from ad…

Mitigation only
Fix from $1,600 2025-10-14
Endpoint Manager HIGH 8.8
CVE-2025-9713EPSS 15%

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User int…

Fix: 2024+
Fix from $1,950 2025-10-13
Docsys CRITICAL 9.1
CVE-2025-11631

A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDo…

Fix: after 2.02.36
Fix from $2,300 2025-10-12
Docsys CRITICAL 9.8
CVE-2025-11630

A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component Fil…

Fix: after 2.02.36
Fix from $2,300 2025-10-12
Configurator HIGH 7.5
CVE-2025-61884 KEVEPSS 98%

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3…

Fix: after 12.2.14
Fix from $1,950 2025-10-12
Moneyprinterturbo HIGH 8.8
CVE-2025-11607

A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controll…

Fix: after 1.2.6
Fix from $1,950 2025-10-11
Unclassified CRITICAL 9.8
CVE-2025-6439

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrar…

Mitigation only
Fix from $2,300 2025-10-11
Android HIGH 7.8
CVE-2025-21048

Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2025-10-10
Project Center MEDIUM 6.4
CVE-2025-35053

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an aut…

Fix: after 2024.3
Fix from $1,600 2025-10-09
Project Center HIGH 8.8
CVE-2025-35055

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writab…

Fix: 2023.1+
Fix from $1,950 2025-10-09
Project Center MEDIUM 5.0
CVE-2025-35056

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the spec…

Fix: 2024.1+
Fix from $1,600 2025-10-09
Unclassified HIGH 7.2
CVE-2025-34248

D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due t…

Mitigation only
Fix from $1,950 2025-10-09
Unclassified CRITICAL 9.6
CVE-2025-10284

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting …

Mitigation only
Fix from $2,300 2025-10-09
Unclassified CRITICAL 9.6
CVE-2025-10283

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

Mitigation only
Fix from $2,300 2025-10-09
Checkmk MEDIUM 6.5
CVE-2025-39664

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define…

Fix: 2.2.0+
Fix from $1,600 2025-10-09
Unclassified CRITICAL 9.8
CVE-2025-7526

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due …

Mitigation only
Fix from $2,300 2025-10-09
Flowise CRITICAL 9.9
CVE-2025-61913EPSS 12%

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…

Fix: 3.0.8+
Fix from $2,300 2025-10-08
Llama Factory HIGH 8.1
CVE-2025-61784

LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat A…

Fix: 0.9.4+
Fix from $1,950 2025-10-07
Data Domain Operating System MEDIUM 6.0
CVE-2025-43934

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…

Fix: 7.10.1.70 / 7.13.1.40+
Fix from $1,600 2025-10-07
Data Domain Operating System HIGH 7.5
CVE-2025-43889

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release Versions 7.1…

Fix: 7.10.1.70 / 7.13.1.40+
Fix from $1,950 2025-10-07
Cmc HIGH 8.1
CVE-2025-40889

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated u…

Fix: 25.2.0+
Fix from $1,950 2025-10-07
Cmc MEDIUM 5.4
CVE-2025-3718

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. …

Fix: 25.2.0+
Fix from $1,600 2025-10-07
Sonoma D12 Firmware MEDIUM 5.7
CVE-2025-60969

Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sen…

Mitigation only
Fix from $1,600 2025-10-06
Unclassified MEDIUM 5.3
CVE-2025-11336

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown…

Mitigation only
Fix from $1,600 2025-10-06
Unclassified MEDIUM 5.3
CVE-2025-11337

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneRepor…

Mitigation only
Fix from $1,600 2025-10-06
Baggage Analytics HIGH 7.5
CVE-2025-58591

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerabl…

Mitigation only
Fix from $1,950 2025-10-06
Baggage Analytics HIGH 7.5
CVE-2025-58590

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

Fix: after 4.6.1
Fix from $1,950 2025-10-06
Unclassified MEDIUM 5.8
CVE-2025-8917

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extrac…

Patch available
Fix from $1,600 2025-10-05
Zenml HIGH 7.8
CVE-2025-8406

ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_director…

Fix: 0.84.2+
Fix from $1,950 2025-10-05
Qsync Central MEDIUM 6.5
CVE-2025-33034

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 5.0.0.1+
Fix from $1,600 2025-10-03