Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.7
CVE-2025-61666

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between v…

Mitigation only
Fix from $1,950 2025-10-02
E Tms HIGH 7.5
CVE-2025-59744

Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only within the web root using the “doc…

Mitigation only
Fix from $1,950 2025-10-02
Lxd MEDIUM 6.5
CVE-2025-54293

Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on …

Fix: 5.21.4 / 6.5+
Fix from $1,600 2025-10-02
Unclassified HIGH 8.8
CVE-2025-11221

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTON…

Mitigation only
Fix from $1,950 2025-10-02
Unclassified HIGH 8.8
CVE-2025-11020

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of…

Mitigation only
Fix from $1,950 2025-10-02
Unclassified MEDIUM 6.5
CVE-2025-11182

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE Chang…

Mitigation only
Fix from $1,600 2025-10-02
Unclassified MEDIUM 6.3
CVE-2025-11233

Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle path separators, causing the …

Patch available
Fix from $1,600 2025-10-01
Unclassified MEDIUM 6.5
CVE-2025-8559

The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.1 via the 'theme' paramete…

Mitigation only
Fix from $1,600 2025-09-30
Freshrss MEDIUM 5.3
CVE-2025-61586

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, a…

Fix: 1.27.0+
Fix from $1,600 2025-09-30
Digital Experience Platform HIGH 8.2
CVE-2025-43813

Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported vers…

Fix: 7.3 / 7.4.3.108+
Fix from $1,950 2025-09-29
Zhiyou Erp CRITICAL 9.8
CVE-2025-11139

A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.F…

Fix: after 11.0
Fix from $2,300 2025-09-29
Farm Management System CRITICAL 9.8
CVE-2025-11079

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation r…

Mitigation only
Fix from $2,300 2025-09-27
Datatables MEDIUM 5.3
CVE-2025-11031

A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/resources/examples.php. This man…

Fix: 1.10.15+
Fix from $1,600 2025-09-26
Water Conservancy Informatization HIGH 7.5
CVE-2025-11018

A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/..…

No fix yet
Fix from $1,950 2025-09-26
Unclassified HIGH 7.7
CVE-2025-59002

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Tr…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified MEDIUM 6.5
CVE-2025-10307

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat…

Mitigation only
Fix from $1,600 2025-09-26
Unclassified HIGH 7.3
CVE-2025-10951

A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vulnerability is the function log…

Mitigation only
Fix from $1,950 2025-09-25
Unclassified HIGH 8.6
CVE-2025-10449

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Por…

Mitigation only
Fix from $1,950 2025-09-25
Unclassified HIGH 8.7
CVE-2025-59343

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the des…

Patch available
Fix from $1,950 2025-09-24
Datart HIGH 7.1
CVE-2025-56815

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

No fix yet
Fix from $1,950 2025-09-24
Datart HIGH 8.8
CVE-2025-56816

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML …

No fix yet
Fix from $1,950 2025-09-24
Unclassified MEDIUM 6.1
CVE-2025-59825

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-tar, tar archives may extract…

Patch available
Fix from $1,600 2025-09-23
Unclassified CRITICAL 9.4
CVE-2025-9963

A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with root permissions. This way the…

Mitigation only
Fix from $2,300 2025-09-23
Papermark MEDIUM 6.5
CVE-2025-57682

Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through …

Fix: after 0.20.0
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.3
CVE-2025-10777

A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /downloadas/. Executing manipul…

Mitigation only
Fix from $1,600 2025-09-22
Mattermost Server HIGH 7.2
CVE-2025-9079

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory pat…

Fix: 9.11.18 / 10.5.9+
Fix from $1,950 2025-09-19
Automation Platform CRITICAL 9.1
CVE-2025-57644

Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe…

Mitigation only
Fix from $2,300 2025-09-19
Sync In Server MEDIUM 5.3
CVE-2025-56869

Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via Files…

Fix: after 1.1.1
Fix from $1,600 2025-09-19
Water Conservancy Informatization HIGH 7.5
CVE-2025-10708

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this vulnerability is an unknown…

No fix yet
Fix from $1,950 2025-09-19
Water Conservancy Informatization HIGH 7.5
CVE-2025-10709

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is some unknown functionality of th…

No fix yet
Fix from $1,950 2025-09-19