Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.0
CVE-2025-32018

Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of…

Mitigation only
Fix from $1,950 2025-04-08
Fortiweb HIGH 7.2
CVE-2025-25254

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version…

Fix: 7.4.7 / 7.6.3+
Fix from $1,950 2025-04-08
7kt Pac1260 Data Manager Firmware HIGH 7.5
CVE-2024-41792

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a path travers…

Mitigation only
Fix from $1,950 2025-04-08
Unclassified MEDIUM 6.5
CVE-2025-2519

The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient fi…

Mitigation only
Fix from $1,600 2025-04-08
Youkefu CRITICAL 9.8
CVE-2025-3381

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMControlle…

No fix yet
Fix from $2,300 2025-04-07
Unclassified HIGH 7.7
CVE-2025-3424

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through …

Mitigation only
Fix from $1,950 2025-04-07
Harmonyos HIGH 7.5
CVE-2025-31174

Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mitigation only
Fix from $1,950 2025-04-07
Opencms MEDIUM 5.3
CVE-2025-3317

A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown fun…

Mitigation only
Fix from $1,600 2025-04-06
Unclassified CRITICAL 9.8
CVE-2025-2941

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path vali…

Mitigation only
Fix from $2,300 2025-04-05
Unclassified HIGH 8.1
CVE-2025-2270

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc…

Mitigation only
Fix from $1,950 2025-04-04
Unclassified MEDIUM 6.5
CVE-2025-31800

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in publitio Publitio publitio allows Path Traversal.This…

Mitigation only
Fix from $1,600 2025-04-03
Unclassified MEDIUM 5.9
CVE-2025-31554

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso docxpresso allows Absolute Path…

Mitigation only
Fix from $1,600 2025-04-03
Unclassified MEDIUM 6.5
CVE-2025-30596

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file include-file allows Path Trave…

Mitigation only
Fix from $1,600 2025-04-03
Opensis CRITICAL 9.8
CVE-2025-22926

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna…

Fix: after 9.1
Fix from $2,300 2025-04-03
Opensis CRITICAL 9.1
CVE-2025-22927

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna…

Fix: after 9.1
Fix from $2,300 2025-04-03
Opensis HIGH 8.8
CVE-2025-22923

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /…

Fix: after 9.1
Fix from $1,950 2025-04-02
Document Server MEDIUM 6.7
CVE-2023-46988

Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt…

Fix: 8.0.1+
Fix from $1,600 2025-04-01
Unclassified CRITICAL 9.9
CVE-2025-30841

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows …

Mitigation only
Fix from $2,300 2025-04-01
Yeswiki HIGH 7.5
CVE-2025-31131EPSS 5%

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on …

Fix: 4.5.2+
Fix from $1,950 2025-04-01
Js Help Desk HIGH 7.5
CVE-2025-30882

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Tr…

Fix: 2.9.2+
Fix from $1,950 2025-04-01
Unclassified HIGH 8.6
CVE-2025-30910

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager cm-downloa…

Mitigation only
Fix from $1,950 2025-04-01
Js Help Desk CRITICAL 9.1
CVE-2025-30878

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Tr…

Fix: 2.9.3+
Fix from $2,300 2025-04-01
Unclassified HIGH 7.5
CVE-2025-30793

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-fe…

Mitigation only
Fix from $1,950 2025-04-01
Unclassified MEDIUM 6.5
CVE-2025-30594

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in samsk Include URL include-url allows Path Traversal.T…

Mitigation only
Fix from $1,600 2025-04-01
Unclassified MEDIUM 5.3
CVE-2025-3043

A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the function preHandle of the fil…

Mitigation only
Fix from $1,600 2025-04-01
Ipados MEDIUM 5.5
CVE-2025-30470

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, ma…

Fix: 2.4 / 13.7.5+
Fix from $1,600 2025-03-31
Completepbx HIGH 8.3
CVE-2025-30005

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additional…

Fix: 5.2.36.1+
Fix from $1,950 2025-03-31
Completepbx MEDIUM 6.5
CVE-2025-2292

Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This …

Fix: 5.2.36.1+
Fix from $1,600 2025-03-31
Unclassified HIGH 8.7
CVE-2025-3021

Path Traversal vulnerability in e-solutions e-management. This vulnerability could allow an attacker to access confidential files outside the expecte…

Mitigation only
Fix from $1,950 2025-03-31
Chestnutcms HIGH 7.5
CVE-2025-2917

A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cm…

Fix: after 1.5.3
Fix from $1,950 2025-03-28