Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Ipx CRITICAL 9.8
CVE-2025-54387

IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used t…

Fix: 1.3.2 / 2.1.1+
Fix from $2,300 2025-08-05
Claude Code CRITICAL 9.1
CVE-2025-54794

Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, …

Fix: 0.2.111+
Fix from $2,300 2025-08-05
Vvvebjs MEDIUM 5.0
CVE-2025-8522

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of …

Fix: after 2.0.4
Fix from $1,600 2025-08-04
Unclassified MEDIUM 5.3
CVE-2025-8516

A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFacto…

Mitigation only
Fix from $1,600 2025-08-04
Woffice HIGH 7.5
CVE-2025-7694

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_d…

Fix: 5.4.27+
Fix from $1,950 2025-08-02
Traefik CRITICAL 9.8
CVE-2025-54386

Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability …

Fix: 2.11.7 / 3.4.4+
Fix from $2,300 2025-08-02
Unclassified MEDIUM 6.9
CVE-2013-10062

A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05)…

No fix yet
Fix from $1,600 2025-08-01
Unclassified MEDIUM 6.9
CVE-2013-10063

A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded web server. Authenticated atta…

No fix yet
Fix from $1,600 2025-08-01
Unclassified HIGH 8.5
CVE-2013-10046

A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code…

No fix yet
Fix from $1,950 2025-08-01
Ilx 507 Firmware HIGH 8.0
CVE-2025-8480

Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected in…

Mitigation only
Fix from $1,950 2025-08-01
Document Management System MEDIUM 5.4
CVE-2025-8433

A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the f…

No fix yet
Fix from $1,600 2025-08-01
Qconvergeconsole CRITICAL 9.4
CVE-2025-8426

Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allow…

Mitigation only
Fix from $2,300 2025-07-31
Unclassified HIGH 8.8
CVE-2014-125125

A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the han…

No fix yet
Fix from $1,950 2025-07-31
Powercms HIGH 7.2
CVE-2025-46359

A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by r…

Fix: 4.61 / 5.31+
Fix from $1,950 2025-07-31
Powercms MEDIUM 6.5
CVE-2025-41396

A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product user.

Fix: 4.61 / 5.31+
Fix from $1,600 2025-07-31
Shio CRITICAL 9.8
CVE-2025-8343

A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the…

Fix: after 0.3.8
Fix from $2,300 2025-07-31
Unclassified HIGH 7.2
CVE-2025-54433

Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ing…

Patch available
Fix from $1,950 2025-07-30
macOS HIGH 7.8
CVE-2025-43196

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A…

Fix: 13.7.7 / 14.7.7+
Fix from $1,950 2025-07-30
macOS MEDIUM 6.2
CVE-2025-43191

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A…

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-07-30
Tileserver Php HIGH 8.2
CVE-2025-44137

MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles …

Patch available
Fix from $1,950 2025-07-29
Data Management Server Firmware CRITICAL 9.1
CVE-2025-53081

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesys…

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $2,300 2025-07-29
Data Management Server Firmware MEDIUM 6.5
CVE-2025-53080

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers …

Fix: 2.3.13.1 / 2.6.14.1+
Fix from $1,600 2025-07-29
Unclassified HIGH 8.1
CVE-2025-6989

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in …

Mitigation only
Fix from $1,950 2025-07-26
Tableau Server HIGH 8.5
CVE-2025-52452

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc a…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Chancms MEDIUM 5.4
CVE-2025-8132

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function delfile of the f…

Fix: 3.1.3+
Fix from $1,600 2025-07-25
Unclassified HIGH 8.1
CVE-2025-7640

The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to…

Mitigation only
Fix from $1,950 2025-07-24
Unclassified HIGH 8.7
CVE-2018-25113

An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. The vulnerability allows remot…

No fix yet
Fix from $1,950 2025-07-23
Unclassified HIGH 8.7
CVE-2010-10012

A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbi…

No fix yet
Fix from $1,950 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54450

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54453

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23