Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Localsend HIGH 8.8
CVE-2025-27142

LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over their local network without need…

Fix: 1.17.0+
Fix from $1,950 2025-02-25
Wp Job Portal HIGH 8.8
CVE-2025-26935

Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal…

Fix: after 2.2.8
Fix from $1,950 2025-02-25
Unclassified HIGH 7.5
CVE-2025-26905

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik allows PHP Local File Inclusi…

Mitigation only
Fix from $1,950 2025-02-25
Unclassified HIGH 8.6
CVE-2025-26752

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-s…

Mitigation only
Fix from $1,950 2025-02-25
Unclassified HIGH 7.5
CVE-2025-26753

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-s…

Mitigation only
Fix from $1,950 2025-02-25
Mattermost Server MEDIUM 6.5
CVE-2025-20051

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicat…

Fix: 9.11.8 / 10.2.3+
Fix from $1,600 2025-02-24
Mattermost Server HIGH 7.5
CVE-2025-25279EPSS 24%

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boar…

Fix: 9.11.8 / 10.2.3+
Fix from $1,950 2025-02-24
Best Church Management Software CRITICAL 9.1
CVE-2025-1599

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unk…

No fix yet
Fix from $2,300 2025-02-24
Online Nurse Hiring System CRITICAL 9.1
CVE-2025-1588

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of th…

Mitigation only
Fix from $2,300 2025-02-23
Graphql Mesh Cli HIGH 7.5
CVE-2025-27098

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, su…

Fix: 0.3.19 / 0.82.22+
Fix from $1,950 2025-02-20
Unclassified MEDIUM 6.5
CVE-2024-55457

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulat…

Mitigation only
Fix from $1,600 2025-02-20
Openpages With Watson MEDIUM 6.5
CVE-2024-49780

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges …

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,600 2025-02-20
Ghosts HIGH 7.5
CVE-2025-27092

GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was …

Fix: 8.2.7.90+
Fix from $1,950 2025-02-19
Unclassified HIGH 8.5
CVE-2025-24965

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into e…

Patch available
Fix from $1,950 2025-02-19
Wegia HIGH 7.5
CVE-2025-26616

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …

Fix: 3.2.14+
Fix from $1,950 2025-02-18
Wegia HIGH 7.5
CVE-2025-26615

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …

Fix: 3.2.14+
Fix from $1,950 2025-02-18
Unclassified HIGH 8.6
CVE-2025-22663

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-web…

Mitigation only
Fix from $1,950 2025-02-18
Unclassified HIGH 8.7
CVE-2025-25284

The ZOO-Project is an open source processing platform, released under MIT/X11 Licence. A vulnerability in ZOO-Project's WPS (Web Processing Service) …

Patch available
Fix from $1,950 2025-02-18
Unclassified MEDIUM 5.7
CVE-2025-1035EPSS 10%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating W…

Mitigation only
Fix from $1,600 2025-02-18
Keap Official Opt In Forms CRITICAL 9.8
CVE-2024-13725

The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service…

Fix: after 2.0.1
Fix from $2,300 2025-02-18
Dropshipping Connector For Woocommerce MEDIUM 5.3
CVE-2024-13538

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.…

Fix: after 1.9.19
Fix from $1,600 2025-02-18
Actionwear Products Sync MEDIUM 5.3
CVE-2024-13535

The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the …

Fix: 2.3.3+
Fix from $1,600 2025-02-18
Luxcal Web Calendar MEDIUM 5.3
CVE-2025-25223

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. …

Fix: 5.3.3l / 5.3.3m+
Fix from $1,600 2025-02-18
Cmseasy HIGH 8.1
CVE-2025-1336

A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in t…

No fix yet
Fix from $1,950 2025-02-16
Cmseasy HIGH 8.1
CVE-2025-1335

A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admi…

No fix yet
Fix from $1,950 2025-02-16
Bit Assist MEDIUM 6.5
CVE-2025-0822

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it p…

Fix: 1.5.3+
Fix from $1,600 2025-02-15
Feminer Wms HIGH 7.5
CVE-2025-25997

Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.

No fix yet
Fix from $1,950 2025-02-14
Unclassified HIGH 8.7
CVE-2025-25295

Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized fi…

Patch available
Fix from $1,950 2025-02-14
Power Hardware Management Console MEDIUM 6.5
CVE-2024-56477

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a …

Mitigation only
Fix from $1,600 2025-02-14
Unclassified CRITICAL 9.1
CVE-2025-1127

The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the fil…

No fix yet
Fix from $2,300 2025-02-13