Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.6
CVE-2024-54291

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass pluginpass-pro-plugintheme-licensin…

Mitigation only
Fix from $1,950 2025-03-28
Unclassified MEDIUM 6.5
CVE-2025-27716

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB storage fil…

Mitigation only
Fix from $1,600 2025-03-28
Unclassified HIGH 8.8
CVE-2025-27718

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharin…

Mitigation only
Fix from $1,950 2025-03-28
Unclassified HIGH 8.1
CVE-2025-27932

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-shar…

Mitigation only
Fix from $1,950 2025-03-28
Drag And Drop Multiple File Upload Contact Form 7 HIGH 8.8
CVE-2025-2328

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…

Fix: 1.3.8.8+
Fix from $1,950 2025-03-28
Unclassified CRITICAL 9.8
CVE-2025-2294EPSS 78%

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_…

Mitigation only
Fix from $2,300 2025-03-28
Unclassified HIGH 7.5
CVE-2024-12905

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal").…

Patch available
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30895

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP L…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified MEDIUM 6.5
CVE-2025-1310

The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_g…

Mitigation only
Fix from $1,600 2025-03-26
Ghostscript CRITICAL 9.8
CVE-2025-27837

An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 charac…

Fix: 10.05.0+
Fix from $2,300 2025-03-25
Openemr HIGH 7.5
CVE-2025-29789

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Di…

Fix: 7.0.3+
Fix from $1,950 2025-03-25
Core Flight System HIGH 7.5
CVE-2025-25371

NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.

No fix yet
Fix from $1,950 2025-03-25
Unclassified HIGH 7.5
CVE-2025-30567

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affec…

Mitigation only
Fix from $1,950 2025-03-25
Unclassified HIGH 8.2
CVE-2025-27147

The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWa…

Patch available
Fix from $1,950 2025-03-25
Ruoyi Vue Pro MEDIUM 5.4
CVE-2025-2744

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin…

No fix yet
Fix from $1,600 2025-03-25
Ruoyi Vue Pro HIGH 8.1
CVE-2025-2742

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api…

No fix yet
Fix from $1,950 2025-03-25
Ruoyi Vue Pro HIGH 8.1
CVE-2025-2743

A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing…

No fix yet
Fix from $1,950 2025-03-25
Ruoyi Vue Pro CRITICAL 9.1
CVE-2025-2708

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-ap…

No fix yet
Fix from $2,300 2025-03-24
Xperience HIGH 7.2
CVE-2025-2749 KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative …

Fix: after 13.0.178
Fix from $1,950 2025-03-24
Ruoyi Vue Pro CRITICAL 9.1
CVE-2025-2707

A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functi…

No fix yet
Fix from $2,300 2025-03-24
Openslides MEDIUM 6.5
CVE-2025-30343

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The int…

Fix: 4.2.5+
Fix from $1,600 2025-03-21
Unclassified HIGH 7.1
CVE-2024-9597

A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory o…

Mitigation only
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-9362

An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retri…

Mitigation only
Fix from $1,950 2025-03-20
Superagi HIGH 8.8
CVE-2024-9415

A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an at…

No fix yet
Fix from $1,950 2025-03-20
Aim CRITICAL 9.1
CVE-2024-8769

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path…

Fix: 3.24.0+
Fix from $2,300 2025-03-20
Lollms Web Ui CRITICAL 9.8
CVE-2024-8898

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab…

Patch available
Fix from $2,300 2025-03-20
Lollms Web Ui CRITICAL 9.1
CVE-2024-8581

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the syst…

Patch available
Fix from $2,300 2025-03-20
Agentscope HIGH 7.5
CVE-2024-8438

A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` pa…

No fix yet
Fix from $1,950 2025-03-20
Agentscope HIGH 7.5
CVE-2024-8524

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON …

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 8.1
CVE-2024-8060

OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The …

Mitigation only
Fix from $1,950 2025-03-20