Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Parallels Desktop HIGH 8.8
CVE-2025-31359

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vuln…

No fix yet
Fix from $1,950 2025-06-03
Unclassified MEDIUM 5.3
CVE-2025-41428

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON f…

Mitigation only
Fix from $1,600 2025-06-03
Unclassified HIGH 8.7
CVE-2025-48387

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the s…

Patch available
Fix from $1,950 2025-06-02
Weblaudos HIGH 7.5
CVE-2025-27956

Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.

No fix yet
Fix from $1,950 2025-06-02
Mybb HIGH 7.2
CVE-2025-48940

MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attac…

Fix: 1.8.39+
Fix from $1,950 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37095

A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.1
CVE-2025-37094

A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Astrbot HIGH 7.5
CVE-2025-48957

AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead…

Fix: 3.5.13+
Fix from $1,950 2025-06-02
Planning Analytics Local MEDIUM 6.5
CVE-2025-33004

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

Mitigation only
Fix from $1,600 2025-06-01
Jeewms CRITICAL 9.8
CVE-2025-5385

A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgfo…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Yifang HIGH 7.2
CVE-2025-5381

A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/Fil…

Fix: after 2.0.2
Fix from $1,950 2025-05-31
Unclassified MEDIUM 6.3
CVE-2025-5380

A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f…

Mitigation only
Fix from $1,600 2025-05-31
Newsletters HIGH 7.2
CVE-2025-4857

The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. Th…

Fix: 4.10+
Fix from $1,950 2025-05-31
Traefik CRITICAL 9.1
CVE-2025-47952

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in T…

Fix: 2.11.25 / 3.4.1+
Fix from $2,300 2025-05-30
Mccms HIGH 8.8
CVE-2025-5328

A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sy…

No fix yet
Fix from $1,950 2025-05-29
Sterling Secure Proxy HIGH 7.5
CVE-2024-51453

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a speci…

Fix: after 6.2.0.1
Fix from $1,950 2025-05-28
Pmb CRITICAL 9.8
CVE-2025-48744

In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.

Fix: 8.0.1.2+
Fix from $2,300 2025-05-27
Seccenter Smp 1114p02 HIGH 7.5
CVE-2025-5161

A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function oper…

Fix: after 20250513
Fix from $1,950 2025-05-26
Seccenter Smp 1114p02 HIGH 7.5
CVE-2025-5159

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of…

Fix: after 20250513
Fix from $1,950 2025-05-26
Seccenter Smp 1114p02 HIGH 7.5
CVE-2025-5160

A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the function Download of the file …

Fix: after 20250513
Fix from $1,950 2025-05-26
Seccenter Smp 1114p02 HIGH 7.5
CVE-2025-5158

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function …

Fix: after 20250513
Fix from $1,950 2025-05-25
Seccenter Smp 1114p02 HIGH 7.5
CVE-2025-5157

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of …

Fix: after 20250513
Fix from $1,950 2025-05-25
Wp Job Portal HIGH 7.5
CVE-2025-48273

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path T…

Fix: 2.3.3+
Fix from $1,950 2025-05-23
Unclassified HIGH 7.5
CVE-2025-47603

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo belingogeo allows Path Traversal.T…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified HIGH 8.6
CVE-2025-47535

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-cus…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified HIGH 8.6
CVE-2025-47492

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor F…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified HIGH 8.6
CVE-2025-47512

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainacan allows Path Traversal.This…

Mitigation only
Fix from $1,950 2025-05-23
Unclassified MEDIUM 6.5
CVE-2025-46527

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likecoin allows Path Traversal.Thi…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 7.7
CVE-2025-31053

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-…

Mitigation only
Fix from $1,950 2025-05-23
Hue HIGH 7.5
CVE-2025-3884

Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…

Mitigation only
Fix from $1,950 2025-05-22