Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified CRITICAL 9.4
CVE-2025-58438

internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vu…

Patch available
Fix from $2,300 2025-09-06
Unclassified HIGH 8.1
CVE-2025-9566

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a…

Patch available
Fix from $1,950 2025-09-05
Android MEDIUM 5.5
CVE-2025-48550

In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead …

Patch available
Fix from $1,600 2025-09-04
Apprain MEDIUM 6.5
CVE-2025-41035

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to…

Mitigation only
Fix from $1,600 2025-09-04
Unclassified HIGH 7.7
CVE-2025-58355

Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with unc…

Mitigation only
Fix from $1,950 2025-09-04
Shockline HIGH 7.8
CVE-2025-7975

Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…

Fix: 2025.4.2+
Fix from $1,950 2025-09-02
Mobile Security Framework MEDIUM 6.5
CVE-2025-58162

MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write …

Patch available
Fix from $1,600 2025-09-02
Sim HIGH 8.1
CVE-2025-9801

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manip…

Fix: 0.3.40+
Fix from $1,950 2025-09-01
Unclassified HIGH 7.0
CVE-2025-52861

A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account, they can then exploit the vu…

Mitigation only
Fix from $1,950 2025-08-29
Unclassified HIGH 8.8
CVE-2025-58158

Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact …

Patch available
Fix from $1,950 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-33033

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-33036

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-33037

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-33038

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29
Qts MEDIUM 6.5
CVE-2025-30270

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they ca…

Mitigation only
Fix from $1,600 2025-08-29
Qts MEDIUM 6.5
CVE-2025-30271

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they ca…

Mitigation only
Fix from $1,600 2025-08-29
Unclassified MEDIUM 5.4
CVE-2025-9650

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This affects the function removeFileByPath of the …

Mitigation only
Fix from $1,600 2025-08-29
Unclassified MEDIUM 6.5
CVE-2025-9217

The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_…

Mitigation only
Fix from $1,600 2025-08-29
Nagios Xi HIGH 8.8
CVE-2024-13986

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Cor…

Fix: 2024+
Fix from $1,950 2025-08-28
Unclassified HIGH 7.7
CVE-2025-54029

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export extendons-eo-…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 7.7
CVE-2025-53588

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code G…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 7.5
CVE-2025-58072

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a a…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified MEDIUM 6.5
CVE-2025-54819

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a a…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified CRITICAL 10.0
CVE-2024-13981

LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerabil…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified HIGH 8.7
CVE-2024-13982

SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerabili…

Mitigation only
Fix from $1,950 2025-08-27
Unclassified CRITICAL 10.0
CVE-2024-13984

QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 10.0
CVE-2023-7309

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated M…

Mitigation only
Fix from $2,300 2025-08-27
Nexus Dashboard HIGH 7.2
CVE-2025-20344

A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversa…

Fix: 4.1+
Fix from $1,950 2025-08-27
Abantecart HIGH 7.5
CVE-2025-50971

Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the templ…

No fix yet
Fix from $1,950 2025-08-26
N8n Workflow Collection CRITICAL 9.1
CVE-2025-55526

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

No fix yet
Fix from $2,300 2025-08-26