Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Pre School Enrollment System HIGH 7.5
CVE-2025-50349

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.

No fix yet
Fix from $1,950 2025-06-23
Winrar HIGH 7.8
CVE-2025-6218 KEVEPSS 89%

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…

Fix: 7.12+
Fix from $1,950 2025-06-21
Unclassified CRITICAL 9.3
CVE-2025-34022

A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, T…

No fix yet
Fix from $2,300 2025-06-20
Unclassified HIGH 8.5
CVE-2025-34023

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sani…

No fix yet
Fix from $1,950 2025-06-20
Novel Plus CRITICAL 9.8
CVE-2025-45890

Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter

Fix: 5.1.0+
Fix from $2,300 2025-06-20
Agent HIGH 7.5
CVE-2025-6283

A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the function GET of the file apps/dba…

Fix: 0.3.1+
Fix from $1,950 2025-06-19
Superagi CRITICAL 9.8
CVE-2025-6280

A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachmen…

Fix: after 0.0.14
Fix from $2,300 2025-06-19
Xagent MEDIUM 6.3
CVE-2025-6281

A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality o…

Mitigation only
Fix from $1,600 2025-06-19
Openagents CRITICAL 9.8
CVE-2025-6282

A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is…

Fix: after 2024-11-18
Fix from $2,300 2025-06-19
Upsonic CRITICAL 9.8
CVE-2025-6278

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/s…

Fix: after 0.55.6
Fix from $2,300 2025-06-19
Osv Scalibr MEDIUM 6.5
CVE-2025-5981

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for con…

Fix: 0.1.8+
Fix from $1,600 2025-06-18
Unclassified HIGH 7.5
CVE-2025-50202

Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment vari…

Patch available
Fix from $1,950 2025-06-18
Unclassified HIGH 8.6
CVE-2025-49879

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho litho allows Path Traversal.This issue…

Mitigation only
Fix from $1,950 2025-06-17
Unclassified HIGH 8.6
CVE-2025-49415

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Path Travers…

Mitigation only
Fix from $1,950 2025-06-17
Unclassified MEDIUM 6.3
CVE-2025-34508EPSS 69%

A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticate…

Mitigation only
Fix from $1,600 2025-06-17
Unclassified HIGH 7.8
CVE-2025-6020

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to eleva…

Mitigation only
Fix from $1,950 2025-06-17
Python A2a CRITICAL 9.8
CVE-2025-6167

A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file p…

Fix: after 0.5.5
Fix from $2,300 2025-06-17
Browser CRITICAL 9.8
CVE-2025-6152

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api…

Patch available
Fix from $2,300 2025-06-17
Conda Build CRITICAL 9.8
CVE-2025-32799

Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path trav…

Fix: 25.4.0+
Fix from $2,300 2025-06-16
Digital Experience Platform CRITICAL 9.8
CVE-2025-3594

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA…

Fix: after 7.4.3.4
Fix from $2,300 2025-06-16
Unclassified MEDIUM 6.3
CVE-2025-6108

A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Aff…

No fix yet
Fix from $1,600 2025-06-16
M Files Server MEDIUM 6.5
CVE-2025-5964EPSS 14%

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.

Fix: 24.8.13981.16 / 25.2.14524.9+
Fix from $1,600 2025-06-15
Unclassified CRITICAL 9.1
CVE-2025-6065

The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' t…

Mitigation only
Fix from $2,300 2025-06-14
Unclassified MEDIUM 6.5
CVE-2025-6070

The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() funct…

Mitigation only
Fix from $1,600 2025-06-14
Unclassified MEDIUM 5.9
CVE-2025-4187

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ…

Mitigation only
Fix from $1,600 2025-06-14
Cosmos HIGH 7.5
CVE-2025-28382

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Patch available
Fix from $1,950 2025-06-13
Cosmos CRITICAL 9.1
CVE-2025-28384

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Patch available
Fix from $2,300 2025-06-13
Solon MEDIUM 6.1
CVE-2025-46096

Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component

No fix yet
Fix from $1,600 2025-06-13
Unclassified CRITICAL 9.8
CVE-2025-46783

Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code…

Mitigation only
Fix from $2,300 2025-06-13
Salt HIGH 7.5
CVE-2024-38824

Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

Fix: 3006.12 / 3007.4+
Fix from $1,950 2025-06-13