Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.2 CVE-2025-68476 KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been ide… Patch available Fix from $1,9502025-12-22 HIGH 8.8 CVE-2023-53979 MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code… Mybb No fix yet Fix from $1,9502025-12-22 HIGH 7.5 CVE-2023-53962 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary file… Impact Firmware No fix yet Fix from $1,9502025-12-22 HIGH 7.5 CVE-2025-11540 Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector. Np P502h Firmware Mitigation only Fix from $1,9502025-12-22 MEDIUM 5.5 CVE-2025-14965 A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the function upload/delete of the f… Mitigation only Fix from $1,6002025-12-19 HIGH 7.6 CVE-2025-67442 EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface la… Eve Ng No fix yet Fix from $1,9502025-12-19 HIGH 7.5 CVE-2025-66905 The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A rem… Tkfiles No fix yet Fix from $1,9502025-12-19 MEDIUM 6.5 CVE-2025-14910 A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation re… Br 6208ac Firmware No fix yet Fix from $1,6002025-12-19 CRITICAL 9.1 CVE-2025-68398 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i… Weblate 5.15.1+ Fix from $2,3002025-12-18 MEDIUM 6.5 CVE-2025-68279 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf… Weblate 5.15.1+ Fix from $1,6002025-12-18 HIGH 8.7 CVE-2025-34452EPSS 5% Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vul… Patch available Fix from $1,9502025-12-18 HIGH 7.5 CVE-2025-67653 Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files. Webaccess\/scada Mitigation only Fix from $1,9502025-12-18 CRITICAL 9.1 CVE-2025-14850 Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files. Webaccess\/scada Mitigation only Fix from $2,3002025-12-18 MEDIUM 6.5 CVE-2023-53944 EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root… Webserver No fix yet Fix from $1,6002025-12-18 MEDIUM 6.5 CVE-2025-64235 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue af… Mitigation only Fix from $1,6002025-12-18 HIGH 8.1 CVE-2025-40898 A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authe… Cmc 25.5.0+ Fix from $1,9502025-12-18 HIGH 7.7 CVE-2025-64230 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-protection allows Path Traversal.T… Mitigation only Fix from $1,9502025-12-18 MEDIUM 6.5 CVE-2025-54748 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg allows Path Traversal.This is… Mitigation only Fix from $1,6002025-12-18 HIGH 8.8 CVE-2025-68143EPSS 8% Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to… Model Context Protocol Servers 2025.9.25+ Fix from $1,9502025-12-17 CRITICAL 9.1 CVE-2025-68145EPSS 7% In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository… Model Context Protocol Servers 2025.12.18+ Fix from $2,3002025-12-17 MEDIUM 6.5 CVE-2023-53907 Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitra… Bludit 3.13.1+ Fix from $1,6002025-12-17 HIGH 7.5 CVE-2025-67171 Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal. Ritecms No fix yet Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-67174 A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the ad… Ritecms No fix yet Fix from $1,9502025-12-17 HIGH 8.3 CVE-2025-14727 A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached En… Nginx Ingress Controller Mitigation only Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-68155 @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@v… Patch available Fix from $1,9502025-12-16 CRITICAL 10.0 CVE-2025-63414 A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command exec… Allsky Mitigation only Fix from $2,3002025-12-16 MEDIUM 6.5 CVE-2023-53902 WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating direct… Websitebaker No fix yet Fix from $1,6002025-12-16 MEDIUM 6.5 CVE-2025-65075 WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit… Video Management Software Server after 6.42.4 Fix from $1,6002025-12-16 MEDIUM 6.1 CVE-2025-65076 WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit… Video Management Software Server after 6.42.4 Fix from $1,6002025-12-16 HIGH 7.2 CVE-2025-65074 WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker wit… Video Management Software Server after 6.42.4 Fix from $1,9502025-12-16