Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Allegra HIGH 8.8
CVE-2025-3486

Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary cod…

Fix: 8.1.2+
Fix from $1,950 2025-05-22
Unclassified MEDIUM 5.4
CVE-2025-5029

A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by th…

Mitigation only
Fix from $1,600 2025-05-21
Unclassified CRITICAL 9.8
CVE-2025-4524EPSS 10%

The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, a…

No fix yet
Fix from $2,300 2025-05-21
Unclassified CRITICAL 9.0
CVE-2025-48017

Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files

Mitigation only
Fix from $2,300 2025-05-20
Unclassified HIGH 8.2
CVE-2025-41229

VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation ma…

Mitigation only
Fix from $1,950 2025-05-20
Unclassified MEDIUM 5.9
CVE-2025-3223

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST on Windows (EGD Configuratio…

Mitigation only
Fix from $1,600 2025-05-19
Grand Restaurant CRITICAL 9.8
CVE-2025-32926

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Pa…

Fix: after 7.0
Fix from $2,300 2025-05-19
A Blog Cms HIGH 7.2
CVE-2025-27566

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient…

Fix: 3.0.47 / 3.1.43+
Fix from $1,950 2025-05-19
Student Result Management System CRITICAL 9.1
CVE-2025-4912

A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affected by this vulnerability is a…

No fix yet
Fix from $2,300 2025-05-19
Student Result Management System MEDIUM 5.4
CVE-2025-4898

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects the fu…

Mitigation only
Fix from $1,600 2025-05-18
Unclassified MEDIUM 6.3
CVE-2025-4893

A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. Th…

No fix yet
Fix from $1,600 2025-05-18
Unclassified MEDIUM 6.3
CVE-2025-4868

A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has been rated as critical. Affect…

No fix yet
Fix from $1,600 2025-05-18
Setuptools HIGH 8.8
CVE-2025-47273

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `Pac…

Fix: 78.1.1+
Fix from $1,950 2025-05-17
Online Student Clearance System HIGH 7.5
CVE-2025-4807

A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. …

No fix yet
Fix from $1,950 2025-05-16
Unclassified HIGH 8.7
CVE-2025-40629

PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipula…

Mitigation only
Fix from $1,950 2025-05-16
Student Result Management System MEDIUM 5.4
CVE-2025-4720

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects unknow…

No fix yet
Fix from $1,600 2025-05-15
Unclassified CRITICAL 9.4
CVE-2025-47788

Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controlle…

Patch available
Fix from $2,300 2025-05-15
Unclassified CRITICAL 9.8
CVE-2025-4564

The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via th…

Mitigation only
Fix from $2,300 2025-05-15
Unclassified HIGH 7.2
CVE-2024-13914

The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-mana…

Mitigation only
Fix from $1,950 2025-05-15
Coldfusion MEDIUM 6.8
CVE-2025-43566EPSS 55%

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traver…

Mitigation only
Fix from $1,600 2025-05-13
Azure Ai Document Intelligence Studio CRITICAL 9.8
CVE-2025-30387

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a …

Mitigation only
Fix from $2,300 2025-05-13
Kirby CRITICAL 9.1
CVE-2025-31493

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use…

Fix: 3.9.8.3 / 3.10.1.2+
Fix from $2,300 2025-05-13
Kirby HIGH 7.5
CVE-2025-30207

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that us…

Fix: 3.9.8.3 / 3.10.1.2+
Fix from $1,950 2025-05-13
Upset Gal Web HIGH 7.5
CVE-2025-28055

upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit

No fix yet
Fix from $1,950 2025-05-13
Netalertx HIGH 8.6
CVE-2024-48766EPSS 70%

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to…

Fix: 24.10.12+
Fix from $1,950 2025-05-13
Kirby CRITICAL 9.1
CVE-2025-30159

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use…

Fix: 3.9.8.3 / 3.10.1.2+
Fix from $2,300 2025-05-13
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-4632 KEVEPSS 24%

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wr…

Fix: 21.1052.0+
Fix from $2,300 2025-05-13
Pagure MEDIUM 6.5
CVE-2024-4982

A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could disco…

Fix: 5.14.1+
Fix from $1,600 2025-05-12
Ctcms HIGH 8.1
CVE-2025-4545

A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcm…

No fix yet
Fix from $1,950 2025-05-11
Unclassified MEDIUM 6.3
CVE-2025-4511

A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEnt…

No fix yet
Fix from $1,600 2025-05-10