Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 6.3
CVE-2025-22240

Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated inp…

Mitigation only
Fix from $1,600 2025-06-13
Unclassified MEDIUM 5.6
CVE-2025-22241

File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki…

Mitigation only
Fix from $1,600 2025-06-13
Web Designer HIGH 8.8
CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…

Fix: 16.3.0.0407+
Fix from $1,950 2025-06-12
Unclassified MEDIUM 6.1
CVE-2025-40592

A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Stu…

Mitigation only
Fix from $1,600 2025-06-12
365 Apps HIGH 7.8
CVE-2025-47176

'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-06-10
Erxes MEDIUM 5.4
CVE-2024-57189

In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCrea…

Fix: 1.6.2+
Fix from $1,600 2025-06-10
Erxes MEDIUM 5.4
CVE-2024-57186

In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint…

Fix: 1.6.2+
Fix from $1,600 2025-06-10
Unclassified HIGH 7.7
CVE-2025-37100

A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successf…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified HIGH 7.2
CVE-2025-5740

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes wh…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified HIGH 7.6
CVE-2025-42977

SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privil…

Mitigation only
Fix from $1,950 2025-06-10
Haxcms Php MEDIUM 6.5
CVE-2025-49138

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) …

Fix: 11.0.0+
Fix from $1,600 2025-06-09
Wp Pipes CRITICAL 9.1
CVE-2025-48267

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue …

Fix: 1.4.3+
Fix from $2,300 2025-06-09
Unclassified HIGH 7.5
CVE-2025-48130

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks spice-blocks allows Path Tra…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.5
CVE-2025-48124

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooC…

Mitigation only
Fix from $1,950 2025-06-09
Welcart E Commerce MEDIUM 6.5
CVE-2025-47511

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Pat…

Fix: 2.11.14+
Fix from $1,600 2025-06-09
Unclassified HIGH 8.1
CVE-2025-39473

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebGeniusLab Seofy Core seofy-core allows PHP Local F…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.5
CVE-2025-31635

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup CLEVER lbg-audio11-html5-shoutcast_histo…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.5
CVE-2025-31050

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appthaplugins Apptha Slider Gallery apptha-slider-gal…

Mitigation only
Fix from $1,950 2025-06-09
Allegra HIGH 8.8
CVE-2025-3485

Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

Fix: 8.1.2+
Fix from $1,950 2025-06-06
File Station MEDIUM 6.5
CVE-2025-33035

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vuln…

Fix: 5.5.6.4847+
Fix from $1,600 2025-06-06
Unclassified HIGH 8.1
CVE-2025-3055

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_…

Mitigation only
Fix from $1,950 2025-06-05
Unified Contact Center Express MEDIUM 6.7
CVE-2025-20277

A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on …

Mitigation only
Fix from $1,600 2025-06-04
Thousandeyes Endpoint Agent MEDIUM 5.3
CVE-2025-20259

Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delet…

Fix: 2.3.3+
Fix from $1,600 2025-06-04
Oa System HIGH 7.5
CVE-2025-5545

A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the fun…

No fix yet
Fix from $1,950 2025-06-04
Oa System HIGH 7.5
CVE-2025-5544

A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this …

No fix yet
Fix from $1,950 2025-06-03
Shiyi Blog CRITICAL 9.8
CVE-2025-5509

A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload…

Fix: after 1.2.1
Fix from $2,300 2025-06-03
Unclassified MEDIUM 5.3
CVE-2024-12718

Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extrac…

Patch available
Fix from $1,600 2025-06-03
Unclassified HIGH 7.5
CVE-2025-4138

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me…

Patch available
Fix from $1,950 2025-06-03
Unclassified HIGH 7.5
CVE-2025-4330

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me…

Patch available
Fix from $1,950 2025-06-03
Unclassified CRITICAL 9.4
CVE-2025-4517

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if…

Patch available
Fix from $2,300 2025-06-03