Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2022-50932 Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system … Command Center Rx No fix yet Fix from $1,9502026-01-13 HIGH 7.5 CVE-2022-50890 Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. … Owlfiles No fix yet Fix from $1,9502026-01-13 HIGH 7.5 CVE-2021-47751 CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows … Rich Text Editor after 6.6 Fix from $1,9502026-01-13 MEDIUM 5.5 CVE-2021-47749 YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the '… Youphptube after 7.8 Fix from $1,6002026-01-13 CRITICAL 9.8 CVE-2026-22871 GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract… Guarddog 2.7.1+ Fix from $2,3002026-01-13 HIGH 7.5 CVE-2025-25652 In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversa… Archibus No fix yet Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2025-58693 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoic… Fortivoice 7.0.8 / 7.2.3+ Fix from $1,6002026-01-13 MEDIUM 5.5 CVE-2025-9435 Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module Manageengine Admanager Plus 7.2+ Fix from $1,6002026-01-13 HIGH 7.2 CVE-2026-22786 Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint res… Gin Vue Admin after 2.8.7 Fix from $1,9502026-01-12 MEDIUM 6.5 CVE-2025-66689 A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The v… Pal Mcp Server 9.8.2+ Fix from $1,6002026-01-12 CRITICAL 9.1 CVE-2025-68472EPSS 20% MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the f… Mindsdb 25.11.1+ Fix from $2,3002026-01-12 MEDIUM 6.5 CVE-2025-69267 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Pa… Dx Netops Spectrum 24.3.9+ Fix from $1,6002026-01-12 CRITICAL 9.8 CVE-2026-22685 DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension i… Devtoys 2.0.9.0+ Fix from $2,3002026-01-10 CRITICAL 9.1 CVE-2025-61686EPSS 16% React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node … React Router\/node 2.17.2 / 7.9.4+ Fix from $2,3002026-01-10 MEDIUM 6.5 CVE-2025-67004EPSS 6% ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back af… Couchcms No fix yet Fix from $1,6002026-01-09 HIGH 7.5 CVE-2025-66744 In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing una… Mitigation only Fix from $1,9502026-01-09 MEDIUM 6.5 CVE-2025-66051 Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources b… Ip7137 Firmware Mitigation only Fix from $1,6002026-01-09 CRITICAL 9.8 CVE-2025-69194 A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Meta… Wget2 2.2.1+ Fix from $2,3002026-01-09 MEDIUM 6.5 CVE-2019-25295 The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. Th… Mitigation only Fix from $1,6002026-01-08 MEDIUM 6.2 CVE-2017-20212EPSS 8% FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to rea… No fix yet Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2026-21851 MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a Path Traversal (Zip Slip) vuln… Monai after 1.5.1 Fix from $1,6002026-01-07 MEDIUM 6.5 CVE-2026-21857 REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within… Redaxo 5.20.2+ Fix from $1,6002026-01-07 CRITICAL 9.8 CVE-2025-68705EPSS 7% RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerabi… Rustfs Patch available Fix from $2,3002026-01-07 HIGH 7.5 CVE-2026-0669 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows… Css Patch available Fix from $1,9502026-01-07 MEDIUM 6.5 CVE-2025-14867 The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'source' attribute of the 'flash… Mitigation only Fix from $1,6002026-01-07 HIGH 7.5 CVE-2025-13801 The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via the file parameter. This makes… Mitigation only Fix from $1,9502026-01-07 HIGH 8.8 CVE-2020-36909 SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files u… Snapgear Sg560 Firmware No fix yet Fix from $1,9502026-01-06 HIGH 8.8 CVE-2025-14997 The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in … Mitigation only Fix from $1,9502026-01-06 MEDIUM 6.5 CVE-2026-0604 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7… Mitigation only Fix from $1,6002026-01-06 MEDIUM 5.3 CVE-2025-69226 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existen… Aiohttp 3.13.3+ Fix from $1,6002026-01-05