Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.1
CVE-2025-24888

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. P…

Patch available
Fix from $1,950 2025-02-13
Active Backup For Business Agent MEDIUM 6.5
CVE-2024-47264

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup…

Fix: 2.7.1-3234 / 2.7.1-13234+
Fix from $1,600 2025-02-13
Campress CRITICAL 9.8
CVE-2024-10763

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_a…

Fix: after 1.35
Fix from $2,300 2025-02-13
Unclassified HIGH 7.5
CVE-2024-51376

Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action…

Mitigation only
Fix from $1,950 2025-02-12
Telerik Reporting MEDIUM 5.3
CVE-2024-6097

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolu…

Fix: 19.0.25.211+
Fix from $1,600 2025-02-12
Telerik Ui For Winforms CRITICAL 9.8
CVE-2025-0332

In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressi…

Fix: 2025.1.211+
Fix from $2,300 2025-02-12
Telerik Document Processing Libraries HIGH 8.8
CVE-2024-11343

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system a…

Fix: 2025.1.205+
Fix from $1,950 2025-02-12
Lanproxy MEDIUM 5.1
CVE-2024-57777

Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information

No fix yet
Fix from $1,600 2025-02-11
Commerce HIGH 7.5
CVE-2025-24406

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a R…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2025-02-11
Fortimanager MEDIUM 6.0
CVE-2024-36508

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 throu…

Fix: 7.2.6 / 7.4.3+
Fix from $1,600 2025-02-11
Cloud Services Appliance MEDIUM 5.3
CVE-2024-11771

Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.

Fix: 5.0.5+
Fix from $1,600 2025-02-11
Unclassified HIGH 8.6
CVE-2025-25243

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to downl…

Mitigation only
Fix from $1,950 2025-02-11
Anythingllm HIGH 7.2
CVE-2024-13059EPSS 21%

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the…

Fix: 1.3.1+
Fix from $1,950 2025-02-10
Cmseasy MEDIUM 6.5
CVE-2025-1106

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library li…

No fix yet
Fix from $1,600 2025-02-07
Filevista MEDIUM 6.3
CVE-2024-57248

Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Esca…

No fix yet
Fix from $1,600 2025-02-07
File Explorer MEDIUM 6.5
CVE-2024-55213

Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing functio…

No fix yet
Fix from $1,600 2025-02-07
File Explorer MEDIUM 6.5
CVE-2024-55214

Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download funct…

No fix yet
Fix from $1,600 2025-02-07
One Voice Operations Center HIGH 7.5
CVE-2024-52883

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be…

Fix: 8.4.582+
Fix from $1,950 2025-02-07
Unclassified HIGH 7.5
CVE-2025-25155

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in efreja Music Sheet Viewer music-sheet-viewer allows P…

Mitigation only
Fix from $1,950 2025-02-07
Plugin A\/b Image Optimizer CRITICAL 9.8
CVE-2025-25163

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer images-optimize…

Fix: after 3.3
Fix from $2,300 2025-02-07
Unclassified MEDIUM 5.3
CVE-2024-53586

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecti…

Mitigation only
Fix from $1,600 2025-02-06
Unclassified HIGH 8.1
CVE-2024-54909

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, wher…

Mitigation only
Fix from $1,950 2025-02-06
Whodb CRITICAL 9.1
CVE-2025-24786

WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no p…

Fix: 0.45.0+
Fix from $2,300 2025-02-06
Post And Page Builder MEDIUM 6.5
CVE-2025-0859

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and i…

Fix: 1.27.7+
Fix from $1,600 2025-02-06
App Connect Enterprise MEDIUM 6.5
CVE-2025-0799

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file …

Fix: after 13.0.2.1
Fix from $1,600 2025-02-06
Vitest HIGH 7.5
CVE-2025-24963

Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file sy…

Fix: 2.1.9 / 3.0.4+
Fix from $1,950 2025-02-04
Doris MEDIUM 5.4
CVE-2024-48019

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …

Fix: 2.1.8 / 3.0.3+
Fix from $1,600 2025-02-04
Admiror Gallery HIGH 7.5
CVE-2025-22205

Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.…

Fix: after 4.5.0
Fix from $1,950 2025-02-04
Unclassified HIGH 8.7
CVE-2025-24960

Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This …

Patch available
Fix from $1,950 2025-02-03
Unclassified MEDIUM 6.0
CVE-2025-24961

org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expos…

Patch available
Fix from $1,600 2025-02-03