Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Perfreeblog HIGH 7.5
CVE-2025-29420

PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.

No fix yet
Fix from $1,950 2025-08-25
Unclassified CRITICAL 9.4
CVE-2025-53120EPSS 9%

A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s config…

Mitigation only
Fix from $2,300 2025-08-25
Ruoyi Go MEDIUM 6.5
CVE-2025-9409

A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUpload of the file modules/system…

Fix: after 2.1
Fix from $1,600 2025-08-25
Unclassified MEDIUM 6.5
CVE-2025-8562

The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.4.0 via the 'lens' parameter.…

Patch available
Fix from $1,600 2025-08-25
Unclassified CRITICAL 10.0
CVE-2025-9118

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in o…

Mitigation only
Fix from $2,300 2025-08-25
Tableau Server MEDIUM 6.5
CVE-2025-52450

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc ap…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,600 2025-08-22
Unclassified HIGH 7.8
CVE-2024-56179

In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victims' machines via directory tra…

Mitigation only
Fix from $1,950 2025-08-22
Unclassified HIGH 8.7
CVE-2010-20109

Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversa…

No fix yet
Fix from $1,950 2025-08-21
Unclassified MEDIUM 6.0
CVE-2025-57753

vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The …

Mitigation only
Fix from $1,600 2025-08-21
Unclassified CRITICAL 9.8
CVE-2025-8895

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and…

Mitigation only
Fix from $2,300 2025-08-21
Group Office MEDIUM 5.3
CVE-2025-53505

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is…

Fix: 6.8.119 / 25.0.20+
Fix from $1,600 2025-08-21
Unclassified HIGH 8.7
CVE-2012-10061

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files…

No fix yet
Fix from $1,950 2025-08-20
Soar Qradar Plugin App HIGH 7.5
CVE-2025-36114

IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Fix: after 5.6.0
Fix from $1,950 2025-08-20
Unclassified HIGH 7.2
CVE-2025-54926

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution wh…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 7.5
CVE-2025-54021

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list all…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 8.6
CVE-2025-48158

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field b…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified MEDIUM 6.5
CVE-2025-47650

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path …

Mitigation only
Fix from $1,600 2025-08-20
Unclassified HIGH 8.8
CVE-2025-8141

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the dele…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.8
CVE-2024-44373

A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code e…

Mitigation only
Fix from $2,300 2025-08-19
Unclassified MEDIUM 6.5
CVE-2025-55295

qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability exists in qbit_manage's web AP…

Mitigation only
Fix from $1,600 2025-08-19
Unclassified MEDIUM 6.9
CVE-2025-55214

Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe to generate a project from a s…

Patch available
Fix from $1,600 2025-08-18
Aiven Db Migrate HIGH 7.2
CVE-2025-55282

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to …

Fix: 1.0.7+
Fix from $1,950 2025-08-18
Unclassified HIGH 8.5
CVE-2025-55201

Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write arbitrary files because Copi…

Patch available
Fix from $1,950 2025-08-18
Unclassified MEDIUM 5.9
CVE-2025-41242

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An appli…

No fix yet
Fix from $1,600 2025-08-18
Unclassified HIGH 8.8
CVE-2025-3671

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 v…

Mitigation only
Fix from $1,950 2025-08-16
Unclassified HIGH 7.5
CVE-2025-7641

The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the …

Mitigation only
Fix from $1,950 2025-08-15
Unclassified CRITICAL 9.2
CVE-2025-34154

UnForm Server Manager versions prior to 10.1.12 expose an unauthenticated file read vulnerability via its log file analysis interface. The flaw resid…

Mitigation only
Fix from $2,300 2025-08-13
Umbraco Cms CRITICAL 9.8
CVE-2012-10054

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes …

Fix: 4.7.1+
Fix from $2,300 2025-08-13
Unclassified CRITICAL 9.4
CVE-2011-10010

QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authe…

No fix yet
Fix from $2,300 2025-08-13
Unclassified HIGH 8.7
CVE-2011-10009

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers t…

No fix yet
Fix from $1,950 2025-08-13