Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Chestnutcms HIGH 7.5
CVE-2024-57451

ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any …

Fix: after 1.5.0
Fix from $1,950 2025-02-03
Unclassified HIGH 7.5
CVE-2024-57669

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupContro…

Patch available
Fix from $1,950 2025-02-03
Wolf Wordpress Posts Bulk Editor And Products Manager Professional HIGH 7.2
CVE-2025-24605

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.Thi…

Fix: 1.0.8.6+
Fix from $1,950 2025-02-03
Unclassified HIGH 7.5
CVE-2025-24569

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Pa…

Mitigation only
Fix from $1,950 2025-02-03
Unclassified HIGH 7.5
CVE-2025-23819

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Marco Milesi WP Cloud cloud allows Absolute Path Trav…

Mitigation only
Fix from $1,950 2025-02-03
Cmseasy MEDIUM 6.5
CVE-2025-0973

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/…

No fix yet
Fix from $1,600 2025-02-03
Jupiter X Core MEDIUM 6.5
CVE-2025-0365

The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. …

Fix: 4.8.8+
Fix from $1,600 2025-02-01
Data Domain Operating System HIGH 7.1
CVE-2024-51534

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could po…

Fix: 7.10.1.50 / 7.13.1.20+
Fix from $1,950 2025-02-01
Unclassified CRITICAL 9.6
CVE-2025-24891

Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrit…

Patch available
Fix from $2,300 2025-01-31
Openpanel HIGH 7.5
CVE-2024-53582

An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via…

No fix yet
Fix from $1,950 2025-01-31
Openpanel CRITICAL 9.1
CVE-2024-53537

An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

Fix: after 0.3.4
Fix from $2,300 2025-01-31
Multivendorx CRITICAL 9.8
CVE-2025-0493

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in a…

Fix: 4.2.15+
Fix from $2,300 2025-01-31
Sante Pacs Server MEDIUM 5.3
CVE-2025-0573

Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbit…

Fix: 4.0.10+
Fix from $1,600 2025-01-30
Voyager MEDIUM 5.7
CVE-2024-55415EPSS 16%

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

Fix: after 1.8.0
Fix from $1,600 2025-01-30
Wp Image Uploader CRITICAL 9.1
CVE-2024-13720

The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploade…

Fix: after 1.0.1
Fix from $2,300 2025-01-30
Music Sheet Viewer HIGH 7.5
CVE-2024-13671

The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() …

Fix: after 4.1
Fix from $1,950 2025-01-30
File Selector Android HIGH 7.1
CVE-2024-54461

The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may res…

Fix: 0.5.1+
Fix from $1,950 2025-01-29
Image Picker Android HIGH 7.1
CVE-2024-54462

The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may resu…

Fix: 0.8.12+
Fix from $1,950 2025-01-29
Unclassified MEDIUM 6.6
CVE-2025-0750

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attack…

Mitigation only
Fix from $1,600 2025-01-28
Node.js MEDIUM 5.5
CVE-2025-23084

A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functi…

Fix: 18.20.6 / 20.18.2+
Fix from $1,600 2025-01-28
Cmsimple HIGH 7.5
CVE-2024-57549

CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.

No fix yet
Fix from $1,950 2025-01-27
macOS MEDIUM 5.5
CVE-2024-54520

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A…

Fix: 13.7.2 / 14.7.2+
Fix from $1,600 2025-01-27
Unclassified HIGH 7.8
CVE-2025-0542

Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vul…

Mitigation only
Fix from $1,950 2025-01-25
Cloud Pak System MEDIUM 5.3
CVE-2023-38012

IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories…

Mitigation only
Fix from $1,600 2025-01-25
Abc Notation MEDIUM 6.5
CVE-2024-13550

The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via the 'file' attribute of the 'ab…

Fix: after 6.1.3
Fix from $1,600 2025-01-25
Unclassified MEDIUM 6.5
CVE-2024-12885

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when d…

Mitigation only
Fix from $1,600 2025-01-25
Post Grid\, Slider \& Carousel Ultimate HIGH 8.8
CVE-2024-13409

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclu…

Fix: 1.7+
Fix from $1,950 2025-01-24
Unclassified HIGH 7.5
CVE-2025-23422

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in moaluko Store Locator store-locator allows PHP Local …

Mitigation only
Fix from $1,950 2025-01-24
Ultimate Bootstrap Elements For Elementor CRITICAL 9.8
CVE-2024-13545

The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. …

Fix: after 1.4.9
Fix from $2,300 2025-01-24
Workplace Suite CRITICAL 9.8
CVE-2024-55926

A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By…

Fix: 5.6.701.9+
Fix from $2,300 2025-01-23