Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Onnx CRITICAL 9.1
CVE-2024-7776

A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite…

Fix: after 1.16.1
Fix from $2,300 2025-03-20
Open Webui HIGH 7.2
CVE-2024-7034

In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames.…

No fix yet
Fix from $1,950 2025-03-20
Aim HIGH 7.5
CVE-2024-6851

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleti…

No fix yet
Fix from $1,950 2025-03-20
Unclassified CRITICAL 9.1
CVE-2024-5752

A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a…

Patch available
Fix from $2,300 2025-03-20
Qanything HIGH 7.5
CVE-2024-12866

A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files…

No fix yet
Fix from $1,950 2025-03-20
Unclassified MEDIUM 5.3
CVE-2024-12217

A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_…

Mitigation only
Fix from $1,600 2025-03-20
Llava HIGH 7.5
CVE-2024-12065

A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the s…

No fix yet
Fix from $1,950 2025-03-20
Gpt Academic MEDIUM 6.5
CVE-2024-11037

A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection…

No fix yet
Fix from $1,600 2025-03-20
Db Gpt CRITICAL 9.8
CVE-2024-10902

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This …

No fix yet
Fix from $2,300 2025-03-20
Gpt Academic MEDIUM 6.5
CVE-2024-10948

A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files …

No fix yet
Fix from $1,600 2025-03-20
Db Gpt HIGH 8.2
CVE-2024-10830

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability all…

No fix yet
Fix from $1,950 2025-03-20
Chuanhuchatgpt MEDIUM 6.5
CVE-2024-10707

gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, wh…

No fix yet
Fix from $1,600 2025-03-20
Anythingllm HIGH 7.2
CVE-2024-10513

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to …

Fix: 1.2.2+
Fix from $1,950 2025-03-20
Librechat CRITICAL 9.1
CVE-2024-10361

An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulner…

Patch available
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2025-2505

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. Thi…

Mitigation only
Fix from $2,300 2025-03-20
Eventin HIGH 8.8
CVE-2025-1770

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…

Fix: 4.0.25+
Fix from $1,950 2025-03-20
Applio CRITICAL 9.8
CVE-2025-27782

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to wri…

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Applio CRITICAL 9.8
CVE-2025-27783

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing…

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Applio HIGH 7.5
CVE-2025-27785

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This …

Fix: after 3.2.8-bugfix
Fix from $1,950 2025-03-19
Applio CRITICAL 9.1
CVE-2025-27786

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py t…

Fix: after 3.2.8-bugfix
Fix from $2,300 2025-03-19
Applio HIGH 7.5
CVE-2025-27787

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py …

Fix: after 3.2.8-bugfix
Fix from $1,950 2025-03-19
Soplanning MEDIUM 6.5
CVE-2024-57170

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attack…

No fix yet
Fix from $1,600 2025-03-18
Flexlogger HIGH 8.8
CVE-2025-2449EPSS 32%

NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create a…

Mitigation only
Fix from $1,950 2025-03-18
Softdial Contact Center HIGH 7.5
CVE-2025-2493

Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘…

Mitigation only
Fix from $1,950 2025-03-18
Unclassified MEDIUM 6.6
CVE-2025-0694

Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

Mitigation only
Fix from $1,600 2025-03-18
N Central MEDIUM 5.3
CVE-2024-8510

N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. Thi…

Fix: 2024.6+
Fix from $1,600 2025-03-17
Unclassified HIGH 7.5
CVE-2025-25684

A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the dev…

Mitigation only
Fix from $1,950 2025-03-17
Unclassified HIGH 7.5
CVE-2025-25685

An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding…

Mitigation only
Fix from $1,950 2025-03-17
Unclassified HIGH 7.3
CVE-2025-29787

`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the…

Patch available
Fix from $1,950 2025-03-17
Vblog CRITICAL 9.8
CVE-2025-2363

A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/…

Mitigation only
Fix from $2,300 2025-03-17