Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.5
CVE-2025-27210EPSS 10%

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vul…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified CRITICAL 9.1
CVE-2025-7643

The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions()…

Mitigation only
Fix from $2,300 2025-07-18
Unclassified HIGH 8.8
CVE-2025-3740

The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 vi…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified CRITICAL 9.1
CVE-2025-7712

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip()…

Mitigation only
Fix from $2,300 2025-07-17
Unclassified HIGH 8.7
CVE-2025-34126

A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system w…

No fix yet
Fix from $1,950 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34118

A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unau…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.7
CVE-2025-34120

An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails …

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-31070

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Build…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 7.5
CVE-2025-28955

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce fw…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified HIGH 8.2
CVE-2025-7359

The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t…

Mitigation only
Fix from $1,950 2025-07-16
Conjur MEDIUM 6.5
CVE-2025-49830

Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the poli…

Fix: 1.22.1 / 13.5.1+
Fix from $1,600 2025-07-15
Unclassified HIGH 7.1
CVE-2025-50819

Directory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing the the topi…

Mitigation only
Fix from $1,950 2025-07-15
Unclassified MEDIUM 5.2
CVE-2025-53622

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a …

Patch available
Fix from $1,600 2025-07-15
Unclassified CRITICAL 9.3
CVE-2025-34110

A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbit…

Patch available
Fix from $2,300 2025-07-15
Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks CRITICAL 9.8
CVE-2025-7360

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving d…

Fix: 2.2.2+
Fix from $2,300 2025-07-15
Nwa50ax Firmware HIGH 7.2
CVE-2025-6265

A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authe…

Fix: after 7.10
Fix from $1,950 2025-07-15
Kkfileviewofficeedit HIGH 8.1
CVE-2025-7628

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This…

Fix: after 2019-03-19
Fix from $1,950 2025-07-14
Kkfileviewofficeedit HIGH 7.5
CVE-2025-7626

A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected…

Fix: after 2019-03-19
Fix from $1,950 2025-07-14
Unclassified HIGH 7.1
CVE-2024-26292

An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2…

Mitigation only
Fix from $1,950 2025-07-14
Jsherp HIGH 7.2
CVE-2025-7566

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file…

Fix: after 3.5
Fix from $1,950 2025-07-14
Unclassified MEDIUM 6.3
CVE-2025-7452

A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability af…

Mitigation only
Fix from $1,600 2025-07-11
Unclassified MEDIUM 5.4
CVE-2025-7450

A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the function ResetUserAvatar of the fil…

Mitigation only
Fix from $1,600 2025-07-11
Chall Manager CRITICAL 9.1
CVE-2025-53632

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path o…

Fix: 0.1.4+
Fix from $2,300 2025-07-10
Protop HIGH 8.2
CVE-2025-44177

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An …

No fix yet
Fix from $1,950 2025-07-09
Support Board CRITICAL 9.8
CVE-2025-4828

The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete functi…

Fix: 3.8.1+
Fix from $2,300 2025-07-09
Juju MEDIUM 6.5
CVE-2025-53513

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a cha…

Fix: 2.9.52 / 3.6.8+
Fix from $1,600 2025-07-08
Sinec Nms HIGH 8.8
CVE-2025-40737EPSS 9%

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extractin…

Fix: 4.0+
Fix from $1,950 2025-07-08
Sinec Nms HIGH 8.8
CVE-2025-40738EPSS 9%

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extractin…

Fix: 4.0+
Fix from $1,950 2025-07-08
Unclassified MEDIUM 5.8
CVE-2025-42970

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containi…

Mitigation only
Fix from $1,600 2025-07-08
Dokploy MEDIUM 6.5
CVE-2025-53375

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated…

Fix: 0.23.7+
Fix from $1,600 2025-07-07