Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.5
CVE-2025-10468

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal. This …

Mitigation only
Fix from $1,950 2025-09-19
Dragonfly CRITICAL 9.8
CVE-2025-59352

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…

Fix: 2.1.0+
Fix from $2,300 2025-09-17
Swetrix CRITICAL 9.8
CVE-2025-59304

A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted…

Fix: after 4.0.0
Fix from $2,300 2025-09-17
Thorium MEDIUM 6.5
CVE-2025-35430

CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated att…

Fix: 1.1.2+
Fix from $1,600 2025-09-17
Unclassified MEDIUM 6.5
CVE-2025-9215

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path …

Mitigation only
Fix from $1,600 2025-09-17
Unclassified MEDIUM 6.6
CVE-2025-10050

The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the…

Mitigation only
Fix from $1,600 2025-09-17
Eve X1 Server Firmware HIGH 7.5
CVE-2025-34185

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote atta…

Fix: after 4.7.18.0
Fix from $1,950 2025-09-16
Unclassified MEDIUM 6.9
CVE-2025-59336

Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix…

Patch available
Fix from $1,600 2025-09-16
macOS MEDIUM 5.5
CVE-2025-43314

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sono…

Fix: 14.8 / 15.7+
Fix from $1,600 2025-09-15
Ipados MEDIUM 5.5
CVE-2025-43190

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Se…

Fix: 14.8 / 15.7+
Fix from $1,600 2025-09-15
Freepbx HIGH 7.5
CVE-2025-59056

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web…

Fix: 15.0.38 / 16.0.41+
Fix from $1,950 2025-09-15
Moneyprinterturbo HIGH 7.5
CVE-2025-10472

A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the fi…

Fix: after 1.2.6
Fix from $1,950 2025-09-15
Moneyprinterturbo MEDIUM 6.3
CVE-2025-49089

wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.

Mitigation only
Fix from $1,600 2025-09-15
Unclassified HIGH 7.2
CVE-2025-10176

The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t…

Mitigation only
Fix from $1,950 2025-09-12
10oa MEDIUM 5.3
CVE-2025-10273

A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such man…

No fix yet
Fix from $1,600 2025-09-12
Dialink CRITICAL 10.0
CVE-2025-58321

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Fix: 1.8.0.0+
Fix from $2,300 2025-09-11
Dialink HIGH 7.3
CVE-2025-58320EPSS 14%

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Fix: 1.8.0.0+
Fix from $1,950 2025-09-11
Unclassified HIGH 8.7
CVE-2025-9918

A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions)…

Mitigation only
Fix from $1,950 2025-09-11
Unclassified HIGH 8.0
CVE-2025-9693

The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil…

Mitigation only
Fix from $1,950 2025-09-11
Gpt Academic HIGH 7.5
CVE-2025-10236

A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_f…

Fix: after 3.91
Fix from $1,950 2025-09-11
Unclassified MEDIUM 5.4
CVE-2025-10232

A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the file plugin/filemanager/controll…

Mitigation only
Fix from $1,600 2025-09-10
Unclassified HIGH 7.5
CVE-2025-59049

Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach …

Patch available
Fix from $1,950 2025-09-10
Oa System MEDIUM 5.6
CVE-2025-29592

oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.

No fix yet
Fix from $1,600 2025-09-10
Unclassified HIGH 8.8
CVE-2025-41714

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can ca…

Mitigation only
Fix from $1,950 2025-09-10
Nvdebug CRITICAL 9.8
CVE-2025-23343

The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulner…

Fix: 1.7.0+
Fix from $2,300 2025-09-09
Unclassified MEDIUM 6.8
CVE-2025-47415

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traver…

Mitigation only
Fix from $1,600 2025-09-09
Coldfusion CRITICAL 10.0
CVE-2025-54261EPSS 21%

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traver…

Mitigation only
Fix from $2,300 2025-09-09
Medical Open Network For Ai HIGH 8.8
CVE-2025-58755

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used direc…

Fix: after 1.5.0
Fix from $1,950 2025-09-09
Vite MEDIUM 5.3
CVE-2025-58751

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu…

Fix: 5.4.20 / 6.3.6+
Fix from $1,600 2025-09-08
Unclassified CRITICAL 9.2
CVE-2025-5993

ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable para…

Mitigation only
Fix from $2,300 2025-09-08