Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.8
CVE-2025-2158

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all ve…

Mitigation only
Fix from $1,950 2025-05-10
Unclassified MEDIUM 5.9
CVE-2025-3897

The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' fun…

Mitigation only
Fix from $1,600 2025-05-09
Unclassified HIGH 7.2
CVE-2025-4206

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deleti…

Mitigation only
Fix from $1,950 2025-05-09
Unclassified HIGH 8.3
CVE-2025-4377

Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.…

Mitigation only
Fix from $1,950 2025-05-09
Ap Pagebuilder HIGH 7.5
CVE-2024-6648

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_it…

Fix: 4.0.0+
Fix from $1,950 2025-05-08
Sma 100 Firmware HIGH 8.8
CVE-2025-32820

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo…

Fix: 10.2.1.15-81sv+
Fix from $1,950 2025-05-07
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2025-20187

A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remo…

Mitigation only
Fix from $1,600 2025-05-07
Members CRITICAL 9.1
CVE-2025-20949

Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Sa…

Fix: 5.0.00.11+
Fix from $2,300 2025-05-07
Misskey HIGH 7.5
CVE-2025-46559

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api`…

Fix: 2025.4.1+
Fix from $1,950 2025-05-05
Foxcms CRITICAL 9.1
CVE-2025-45238

foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.

No fix yet
Fix from $2,300 2025-05-05
Foxcms MEDIUM 5.3
CVE-2025-45239

An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.

No fix yet
Fix from $1,600 2025-05-05
Unclassified MEDIUM 5.3
CVE-2024-11615

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLangu…

Mitigation only
Fix from $1,600 2025-05-05
Concert MEDIUM 5.3
CVE-2024-55913

IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craf…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Unclassified MEDIUM 6.3
CVE-2025-4185EPSS 11%

A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. This issue affects some unknown processing of the fi…

Mitigation only
Fix from $1,600 2025-05-02
Unclassified MEDIUM 6.3
CVE-2025-4186

A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown function of the file /?g=route_isp…

Mitigation only
Fix from $1,600 2025-05-02
Java Server MEDIUM 5.4
CVE-2025-4178

A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and classified as critical. This issue…

Fix: after 2019-09-22
Fix from $1,600 2025-05-01
Unclassified MEDIUM 6.3
CVE-2025-4175

A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uplo…

No fix yet
Fix from $1,600 2025-05-01
Vite MEDIUM 5.3
CVE-2025-46565

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project …

Fix: 4.5.14 / 5.4.19+
Fix from $1,600 2025-05-01
Joplin HIGH 7.5
CVE-2025-27409

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …

Fix: 3.3.3+
Fix from $1,950 2025-04-30
Firefox HIGH 8.8
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking be…

Fix: 115.23.0 / 128.10.0+
Fix from $1,950 2025-04-29
Unclassified HIGH 8.1
CVE-2025-26692

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited,…

Mitigation only
Fix from $1,950 2025-04-28
Unclassified MEDIUM 6.5
CVE-2025-27937

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited,…

Mitigation only
Fix from $1,600 2025-04-28
Teamcity CRITICAL 9.8
CVE-2025-46433

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

Fix: 2025.03.1+
Fix from $2,300 2025-04-25
Unclassified MEDIUM 6.5
CVE-2025-28354

An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a cra…

Mitigation only
Fix from $1,600 2025-04-25
Unclassified HIGH 7.5
CVE-2025-1565

The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/pea…

Mitigation only
Fix from $1,950 2025-04-25
Unclassified HIGH 7.2
CVE-2025-3300

The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified CRITICAL 9.1
CVE-2025-3065

The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, an…

Mitigation only
Fix from $2,300 2025-04-24
Jmix Framework MEDIUM 6.5
CVE-2025-32950

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, att…

Fix: 1.6.2 / 2.4.0+
Fix from $1,600 2025-04-22
Commvault CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…

Fix: 11.38.20+
Fix from $2,300 2025-04-22
Nemo CRITICAL 9.8
CVE-2025-23250

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arb…

Fix: 25.02+
Fix from $2,300 2025-04-22