Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Traefik CRITICAL 9.1
CVE-2025-32431

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vul…

Fix: 2.11.24 / 3.3.6+
Fix from $2,300 2025-04-21
Xy 3820 Firmware CRITICAL 9.8
CVE-2025-29660

A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper in…

No fix yet
Fix from $2,300 2025-04-21
Unclassified CRITICAL 9.2
CVE-2025-0632

Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data v…

Mitigation only
Fix from $2,300 2025-04-21
Pmrs 102 Firmware CRITICAL 9.8
CVE-2025-43928

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the u…

No fix yet
Fix from $2,300 2025-04-20
Mailman HIGH 7.5
CVE-2025-43919

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/…

Fix: after 2.1.39
Fix from $1,950 2025-04-20
Unclassified HIGH 8.8
CVE-2025-3404

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage functi…

Mitigation only
Fix from $1,950 2025-04-19
Unclassified HIGH 8.1
CVE-2025-3520

The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to…

Mitigation only
Fix from $1,950 2025-04-18
Unclassified HIGH 7.5
CVE-2025-39568

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arture B.V. StoreContrl Woocommerce storecontrl-wp-co…

Mitigation only
Fix from $1,950 2025-04-17
Unclassified MEDIUM 5.3
CVE-2025-27299

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Asia MyTicket Events myticket-events allows Path T…

Mitigation only
Fix from $1,600 2025-04-17
Unclassified MEDIUM 6.5
CVE-2025-27283

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Duplicator theme-file-duplicato…

Mitigation only
Fix from $1,600 2025-04-17
Wp Editor HIGH 7.2
CVE-2025-3294

The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1…

Fix: 1.2.9.2+
Fix from $1,950 2025-04-17
Pre School Enrollment System HIGH 7.5
CVE-2025-28072

PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.

No fix yet
Fix from $1,950 2025-04-16
Jeewms MEDIUM 5.5
CVE-2025-29213

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Z…

No fix yet
Fix from $1,600 2025-04-15
Unclassified MEDIUM 6.5
CVE-2025-32779

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0, an attacker with access to t…

Patch available
Fix from $1,600 2025-04-15
Thunderbird MEDIUM 6.3
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /…

Fix: 128.9.2 / 137.0.2+
Fix from $1,600 2025-04-15
Crushftp MEDIUM 5.0
CVE-2025-32103EPSS 18%

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible …

Fix: after 11.3.1
Fix from $1,600 2025-04-15
Agent Zero MEDIUM 6.3
CVE-2025-3547

A vulnerability classified as critical was found in frdel Agent-Zero 0.8.1.2. This vulnerability affects unknown code of the file /get_work_dir_files…

Mitigation only
Fix from $1,600 2025-04-14
Unclassified HIGH 8.1
CVE-2025-3445

A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing …

Mitigation only
Fix from $1,950 2025-04-13
Ipados MEDIUM 6.3
CVE-2023-42961

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14,…

Fix: 12.7 / 13.6+
Fix from $1,600 2025-04-11
Unclassified HIGH 7.5
CVE-2025-32671

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Science Designer print-science-d…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.6
CVE-2025-32633

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset database-toolset allows Path…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.6
CVE-2025-32629

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-B…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.6
CVE-2025-32631

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in oxygensuite Oxygen MyData for WooCommerce oxygen-myda…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.1
CVE-2025-32587

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pickupp WooCommerce Pickupp wc-pickupp allows PHP Loc…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 7.5
CVE-2025-32509

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMinds Simple WP Events simple-wp-events allows Path…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified HIGH 8.1
CVE-2025-2636EPSS 10%

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,…

Mitigation only
Fix from $1,950 2025-04-11
Unclassified MEDIUM 5.9
CVE-2025-31411

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aribhour Linet ERP-Woocommerce Integration linet-erp-…

Mitigation only
Fix from $1,600 2025-04-10
Unclassified MEDIUM 6.5
CVE-2025-32209

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway to…

Mitigation only
Fix from $1,600 2025-04-10
Unclassified HIGH 8.1
CVE-2025-30582

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/CRM dyapress allows PHP Local …

Mitigation only
Fix from $1,950 2025-04-10
Coldfusion HIGH 8.7
CVE-2025-30290EPSS 18%

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traver…

Mitigation only
Fix from $1,950 2025-04-08