Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Helpdeskadvanced HIGH 7.5
CVE-2023-42225

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced HIGH 7.5
CVE-2023-42226

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced HIGH 7.5
CVE-2023-42227

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced MEDIUM 6.5
CVE-2023-42229

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticat…

Fix: after 11.0.33
Fix from $1,600 2025-01-13
Reggie MEDIUM 5.3
CVE-2025-0401

A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/ithei…

Mitigation only
Fix from $1,600 2025-01-13
Unclassified CRITICAL 9.1
CVE-2025-22152

Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple component…

Mitigation only
Fix from $2,300 2025-01-10
Post Grid Master CRITICAL 9.8
CVE-2024-11642

The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin …

Fix: after 3.4.12
Fix from $2,300 2025-01-09
Soft Serve HIGH 8.8
CVE-2025-22130

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and…

Fix: 0.8.2+
Fix from $1,950 2025-01-08
Wordpress File Upload HIGH 7.5
CVE-2024-9939

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.…

Fix: 4.24.14+
Fix from $1,950 2025-01-08
Infinitewp Client MEDIUM 5.3
CVE-2024-10585

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter…

Fix: 1.13.1+
Fix from $1,600 2025-01-08
Emui CRITICAL 9.1
CVE-2023-52953

Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiali…

Mitigation only
Fix from $2,300 2025-01-08
Clipbucket CRITICAL 9.1
CVE-2025-21622

ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avata…

Fix: 5.5.1-237+
Fix from $2,300 2025-01-07
Clipbucket HIGH 7.5
CVE-2025-21623

ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the templat…

Fix: 5.5.1-238+
Fix from $1,950 2025-01-07
Unclassified HIGH 7.5
CVE-2024-56286

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.5
CVE-2024-12152

The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.5 via the 'mipl_wc_syn…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.5
CVE-2024-12849EPSS 47%

The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_aj…

Mitigation only
Fix from $1,950 2025-01-07
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2024-41765

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker …

Mitigation only
Fix from $1,600 2025-01-04
Unclassified MEDIUM 5.3
CVE-2024-56514

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to…

Patch available
Fix from $1,600 2025-01-03
Unclassified CRITICAL 9.3
CVE-2024-56198

path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the filters can be bypassed using …

Patch available
Fix from $2,300 2024-12-31
Whatsup Gold MEDIUM 6.5
CVE-2024-12105EPSS 42%

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclo…

Fix: 24.0.2+
Fix from $1,600 2024-12-31
Eventin HIGH 8.8
CVE-2024-56213

Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <…

Fix: 4.0.9+
Fix from $1,950 2024-12-31
Truenas Firmware HIGH 8.8
CVE-2024-11944

iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attacke…

Mitigation only
Fix from $1,950 2024-12-30
Unclassified HIGH 7.5
CVE-2024-54453

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnera…

Mitigation only
Fix from $1,950 2024-12-27
Unclassified HIGH 8.6
CVE-2024-56509

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validat…

Patch available
Fix from $1,950 2024-12-27
Unclassified MEDIUM 5.1
CVE-2024-41887

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can create an NVR log file in a …

No fix yet
Fix from $1,600 2024-12-24
Coldfusion HIGH 8.1
CVE-2024-53961EPSS 14%

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vu…

Mitigation only
Fix from $1,950 2024-12-23
Gogs CRITICAL 9.8
CVE-2024-54148

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access…

Fix: 0.13.1+
Fix from $2,300 2024-12-23
Gogs HIGH 8.8
CVE-2024-55947EPSS 75%

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the…

Fix: 0.13.1+
Fix from $1,950 2024-12-23
Unclassified MEDIUM 6.8
CVE-2024-56331

Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local f…

Patch available
Fix from $1,600 2024-12-20
macOS HIGH 7.5
CVE-2024-44195

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.

Mitigation only
Fix from $1,950 2024-12-20