Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54443

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload …

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54446

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload …

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54438

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload …

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Unclassified HIGH 7.5
CVE-2025-8021

All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files…

Mitigation only
Fix from $1,950 2025-07-23
Unclassified HIGH 7.5
CVE-2025-54140

pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exi…

Patch available
Fix from $1,950 2025-07-22
Viewvc HIGH 7.5
CVE-2025-54141

ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the stan…

Fix: 1.1.31 / 1.2.4+
Fix from $1,950 2025-07-22
Superagi MEDIUM 5.0
CVE-2025-51475

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite ar…

Patch available
Fix from $1,600 2025-07-22
Dagster MEDIUM 6.6
CVE-2025-51481

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary fil…

Patch available
Fix from $1,600 2025-07-22
Aim HIGH 7.0
CVE-2025-51463

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup…

Patch available
Fix from $1,950 2025-07-22
Onnx HIGH 8.8
CVE-2025-51480

Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplyin…

Patch available
Fix from $1,950 2025-07-22
Unclassified HIGH 8.1
CVE-2025-7645

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to arbitrary file deletion du…

Mitigation only
Fix from $1,950 2025-07-22
Ruckus Unleashed CRITICAL 9.8
CVE-2025-46120

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, …

Fix: 10.5.1.0.279 / 200.15.6.212.14+
Fix from $2,300 2025-07-21
Jena HIGH 7.5
CVE-2025-49656

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to…

Fix: 5.5.0+
Fix from $1,950 2025-07-21
Moneyprinterturbo HIGH 7.5
CVE-2025-7896

A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function …

Fix: after 1.2.6
Fix from $1,950 2025-07-20
Simple Backup HIGH 7.5
CVE-2015-10134

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_fil…

Fix: after 2.7.10
Fix from $1,950 2025-07-19
Gi Media Library HIGH 7.5
CVE-2015-10136

The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthe…

Fix: 3.0+
Fix from $1,950 2025-07-19
Unclassified HIGH 7.5
CVE-2025-27210EPSS 10%

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vul…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified CRITICAL 9.1
CVE-2025-7643

The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions()…

Mitigation only
Fix from $2,300 2025-07-18
Unclassified HIGH 8.8
CVE-2025-3740

The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 vi…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified CRITICAL 9.1
CVE-2025-7712

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip()…

Mitigation only
Fix from $2,300 2025-07-17
Unclassified HIGH 8.7
CVE-2025-34126

A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system w…

No fix yet
Fix from $1,950 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34118

A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unau…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34120

An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-31070

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Build…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-28955

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce fw…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.2
CVE-2025-7359

The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t…

Mitigation only
Fix from $1,950 2025-07-16
Conjur MEDIUM 6.5
CVE-2025-49830

Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the poli…

Fix: 1.22.1 / 13.5.1+
Fix from $1,600 2025-07-15
Unclassified HIGH 7.1
CVE-2025-50819

Directory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing the the topi…

Mitigation only
Fix from $1,950 2025-07-15
Unclassified MEDIUM 5.2
CVE-2025-53622

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a …

Patch available
Fix from $1,600 2025-07-15
Unclassified CRITICAL 9.3
CVE-2025-34110

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbit…

Patch available
Fix from $2,300 2025-07-15