Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Nemo CRITICAL 9.8
CVE-2025-23304

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loadin…

Fix: 2.3.2+
Fix from $2,300 2025-08-13
Unclassified HIGH 7.8
CVE-2025-8941

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks …

Mitigation only
Fix from $1,950 2025-08-13
Organization Portal System HIGH 7.5
CVE-2025-8912

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit …

Mitigation only
Fix from $1,950 2025-08-13
Organization Portal System MEDIUM 6.5
CVE-2025-8909

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to …

Mitigation only
Fix from $1,600 2025-08-13
Unclassified MEDIUM 6.5
CVE-2025-0818

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible …

Mitigation only
Fix from $1,600 2025-08-13
Wegia MEDIUM 6.5
CVE-2025-55169

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…

Fix: 3.4.8+
Fix from $1,600 2025-08-12
Fortimanager MEDIUM 6.5
CVE-2024-52964

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 throu…

Fix: 7.0.14 / 7.2.10+
Fix from $1,600 2025-08-12
Azure Stack Hub HIGH 7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

Fix: 1.2406.1.23 / 1.2408.1.50+
Fix from $1,950 2025-08-12
Commerce MEDIUM 5.3
CVE-2025-49559

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pat…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2025-08-12
Kanboard MEDIUM 5.3
CVE-2025-55011

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does no…

Fix: 1.2.47+
Fix from $1,600 2025-08-12
Unclassified HIGH 8.1
CVE-2025-5391

The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_…

Mitigation only
Fix from $1,950 2025-08-12
Unclassified MEDIUM 6.9
CVE-2025-42946

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific tr…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified HIGH 7.5
CVE-2025-25231EPSS 20%

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive inform…

Mitigation only
Fix from $1,950 2025-08-11
Morning CRITICAL 9.8
CVE-2025-8815

A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown…

Mitigation only
Fix from $2,300 2025-08-10
Litemall MEDIUM 5.4
CVE-2025-8753

A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete o…

Fix: after 1.8.0
Fix from $1,600 2025-08-09
Unclassified MEDIUM 6.7
CVE-2025-55149

Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and re…

Mitigation only
Fix from $1,600 2025-08-09
Unclassified HIGH 8.7
CVE-2012-10048

Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() …

No fix yet
Fix from $1,950 2025-08-08
Unclassified CRITICAL 9.8
CVE-2025-52913

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker…

Mitigation only
Fix from $2,300 2025-08-08
Freeflow Core CRITICAL 9.8
CVE-2025-8356EPSS 15%

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lea…

Mitigation only
Fix from $2,300 2025-08-08
Lmeterx CRITICAL 9.1
CVE-2025-8729

A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is the function process_cert_file…

Patch available
Fix from $2,300 2025-08-08
Unclassified MEDIUM 6.5
CVE-2025-8749

Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR Robots allows authenticated us…

Mitigation only
Fix from $1,600 2025-08-08
Exonaut MEDIUM 6.5
CVE-2024-55401

An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.

Fix: 21.6.2.1-1 / 22.4+
Fix from $1,600 2025-08-07
Unclassified HIGH 8.7
CVE-2025-29865

: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.T…

Mitigation only
Fix from $1,950 2025-08-07
Mobile Access MEDIUM 5.4
CVE-2024-52885

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (autho…

Mitigation only
Fix from $1,600 2025-08-06
Android HIGH 7.1
CVE-2025-21015

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

Mitigation only
Fix from $1,950 2025-08-06
Harmonyos MEDIUM 6.5
CVE-2025-54653

Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the v…

Mitigation only
Fix from $1,600 2025-08-06
Harmonyos MEDIUM 5.5
CVE-2025-54652

Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the v…

No fix yet
Fix from $1,600 2025-08-06
Clansphere HIGH 7.5
CVE-2012-10034

ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails …

No fix yet
Fix from $1,950 2025-08-05
Unclassified HIGH 7.1
CVE-2012-10024

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails …

Patch available
Fix from $1,950 2025-08-05
Pyload Ng CRITICAL 9.8
CVE-2025-54802

pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path tra…

Patch available
Fix from $2,300 2025-08-05