Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2025-68953 Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path … Frappe 14.99.6 / 15.88.1+ Fix from $1,9502026-01-05 HIGH 7.5 CVE-2025-68428 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js b… Jspdf 4.0.0+ Fix from $1,9502026-01-05 HIGH 8.8 CVE-2025-66518 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and… Kyuubi 1.10.3+ Fix from $1,9502026-01-05 CRITICAL 9.1 CVE-2025-15449 A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the function delete of the file s… Javamall No fix yet Fix from $2,3002026-01-05 MEDIUM 6.5 CVE-2026-0571 A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function create… Warehouse after 2025-10-06 Fix from $1,6002026-01-02 CRITICAL 9.2 CVE-2026-21440 AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write… Patch available Fix from $2,3002026-01-02 HIGH 7.5 CVE-2025-67160 An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal. Pa4 Firmware No fix yet Fix from $1,9502026-01-02 HIGH 7.5 CVE-2025-59384 A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of u… Qfiling Mitigation only Fix from $1,9502026-01-02 HIGH 7.5 CVE-2025-15432 A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability affects the function downloadSh… Carrental after 2023-04-15 Fix from $1,9502026-01-02 HIGH 7.5 CVE-2022-50792 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access … Impact Firmware No fix yet Fix from $1,9502025-12-30 CRITICAL 9.8 CVE-2022-50796 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path tr… Impact Firmware Mitigation only Fix from $2,3002025-12-30 HIGH 7.5 CVE-2025-61557 nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal. Nixseparatedebuginfod 0.4.1+ Fix from $1,9502025-12-30 HIGH 7.5 CVE-2024-25183 givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php. Vvvebjs No fix yet Fix from $1,9502025-12-29 HIGH 7.5 CVE-2025-67254 NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php. Nagios Xi Mitigation only Fix from $1,9502025-12-29 MEDIUM 6.8 CVE-2025-14728 Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is … Velociraptor 0.75.6+ Fix from $1,6002025-12-29 MEDIUM 6.5 CVE-2025-15187 A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Pe… Greencms after 2.3 Fix from $1,6002025-12-29 HIGH 7.5 CVE-2025-15227 BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute… Bpmflowwebkit 5.0.5+ Fix from $1,9502025-12-29 HIGH 7.5 CVE-2025-15225 WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to r… Wmpro after 5.2 Fix from $1,9502025-12-29 MEDIUM 6.2 CVE-2025-15066 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Travers… Mitigation only Fix from $1,6002025-12-29 HIGH 7.2 CVE-2025-15138 A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php.… Tiny File Manager after 2.6 Fix from $1,9502025-12-28 MEDIUM 6.5 CVE-2024-42718 A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' pa… Croogo No fix yet Fix from $1,6002025-12-26 HIGH 7.3 CVE-2025-15076 A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path… Ch22 Firmware No fix yet Fix from $1,9502025-12-25 HIGH 7.2 CVE-2025-68916 Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution. Netman 208 1.12+ Fix from $1,9502025-12-24 MEDIUM 6.5 CVE-2019-25256 VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary sys… No fix yet Fix from $1,6002025-12-24 HIGH 7.5 CVE-2019-25258 LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files throug… Logicaldoc No fix yet Fix from $1,9502025-12-24 HIGH 8.8 CVE-2019-25246EPSS 18% Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files v… No fix yet Fix from $1,9502025-12-24 HIGH 8.4 CVE-2018-25144 Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attacke… Ipn4g Firmware No fix yet Fix from $1,9502025-12-24 HIGH 7.8 CVE-2025-14420 pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut… Pdf Architect Mitigation only Fix from $1,9502025-12-23 HIGH 7.8 CVE-2025-14413 Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Soda Pdf Desktop Mitigation only Fix from $1,9502025-12-23 HIGH 7.0 CVE-2025-13699 MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Mitigation only Fix from $1,9502025-12-23