Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.8
CVE-2025-5014

The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i…

Mitigation only
Fix from $1,950 2025-07-02
Insight Remote Support HIGH 7.5
CVE-2025-37098EPSS 37%

A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

Fix: 7.15.0.646+
Fix from $1,950 2025-07-01
Unclassified HIGH 8.7
CVE-2025-34058

Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functio…

Mitigation only
Fix from $1,950 2025-07-01
Ruoyi Vue Plus CRITICAL 9.1
CVE-2025-6925

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality…

No fix yet
Fix from $2,300 2025-06-30
Langchain Chatchat HIGH 8.8
CVE-2025-6855

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown p…

Fix: after 0.3.1
Fix from $1,950 2025-06-29
Langchain Chatchat CRITICAL 9.8
CVE-2025-6853

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of…

Fix: after 0.3.1
Fix from $2,300 2025-06-29
Game Users Share Button HIGH 8.8
CVE-2025-6755

The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDelete…

Fix: after 1.3.0
Fix from $1,950 2025-06-28
Vidmov HIGH 8.8
CVE-2025-6379

The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_li…

Fix: 2.3.5+
Fix from $1,950 2025-06-28
Unclassified MEDIUM 6.3
CVE-2025-6774

A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is the function AddTemp of the fil…

Patch available
Fix from $1,600 2025-06-27
Openvpn Cms Flask CRITICAL 9.8
CVE-2025-6776

A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the f…

Fix: 1.2.8+
Fix from $2,300 2025-06-27
Db Gpt HIGH 7.5
CVE-2025-6772

A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /a…

Fix: after 0.7.2
Fix from $1,950 2025-06-27
Unclassified MEDIUM 5.3
CVE-2025-6773

A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_i…

Patch available
Fix from $1,600 2025-06-27
Unclassified HIGH 8.6
CVE-2025-49448

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fastw3b LLC FW Food Menu allows Path Traversal. This…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.7
CVE-2025-24765

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow image-shadow allows Path Traver…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified MEDIUM 6.3
CVE-2025-6731

A vulnerability was found in yzcheng90 X-SpringBoot up to 5.0 and classified as critical. Affected by this issue is the function uploadApk of the fil…

No fix yet
Fix from $1,600 2025-06-26
Pre School Enrollment System MEDIUM 5.4
CVE-2025-50350

PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.

No fix yet
Fix from $1,600 2025-06-26
Unclassified HIGH 8.7
CVE-2025-34047

A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files o…

Mitigation only
Fix from $1,950 2025-06-26
Unclassified HIGH 8.7
CVE-2025-34048

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versio…

No fix yet
Fix from $1,950 2025-06-26
Weiphp HIGH 7.5
CVE-2025-34045

A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Tech…

No fix yet
Fix from $1,950 2025-06-26
Servicestack HIGH 8.1
CVE-2025-6445

ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

Fix: 8.6+
Fix from $1,950 2025-06-25
Unclassified CRITICAL 9.3
CVE-2025-49153

The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.

Mitigation only
Fix from $2,300 2025-06-25
Unclassified MEDIUM 6.6
CVE-2025-52569

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-prov…

Patch available
Fix from $1,600 2025-06-25
Unclassified MEDIUM 6.6
CVE-2025-50178

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certa…

Patch available
Fix from $1,600 2025-06-25
Unclassified HIGH 7.5
CVE-2025-52574

SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by d…

Patch available
Fix from $1,950 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-34040EPSS 14%

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters a…

Mitigation only
Fix from $2,300 2025-06-24
Jmol HIGH 7.5
CVE-2025-34031

A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly p…

Fix: after 6.1
Fix from $1,950 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-52562

Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability i…

Patch available
Fix from $2,300 2025-06-23
Unclassified HIGH 7.2
CVE-2025-23092

Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traver…

Mitigation only
Fix from $1,950 2025-06-23
Unclassified HIGH 7.5
CVE-2025-48026

A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a…

Mitigation only
Fix from $1,950 2025-06-23
Pre School Enrollment System HIGH 7.5
CVE-2025-50348

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.

No fix yet
Fix from $1,950 2025-06-23