Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2025-66449 ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary f… Convertx 0.16.0+ Fix from $1,9502025-12-16 HIGH 8.8 CVE-2025-58173 FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration par… Freshrss 1.27.1+ Fix from $1,9502025-12-16 HIGH 8.8 CVE-2025-60786 A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a c… Icescrum after 7.54 Fix from $1,9502025-12-15 HIGH 8.7 CVE-2025-34181 NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacke… Mitigation only Fix from $1,9502025-12-15 CRITICAL 9.8 CVE-2025-14704EPSS 12% A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The m… N3 Firmware after 2.0.25 Fix from $2,3002025-12-15 MEDIUM 5.3 CVE-2025-14699 A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp… Mitigation only Fix from $1,6002025-12-15 MEDIUM 5.3 CVE-2025-14617 A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown function of the component org.jw.… Mitigation only Fix from $1,6002025-12-13 MEDIUM 5.5 CVE-2025-43463 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3, macOS So… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43465 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.1. An app may b… macOS 26.1+ Fix from $1,6002025-12-12 HIGH 7.2 CVE-2025-67818 An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absol… Weaviate 1.33.4+ Fix from $1,9502025-12-12 MEDIUM 6.5 CVE-2025-12960 The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.1 via the `href` parameter i… Mitigation only Fix from $1,6002025-12-12 MEDIUM 6.5 CVE-2025-13891 The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. Thi… Mitigation only Fix from $1,6002025-12-12 CRITICAL 9.8 CVE-2025-14344 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'p… Mitigation only Fix from $2,3002025-12-12 HIGH 8.8 CVE-2025-12824 The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderb… Mitigation only Fix from $1,9502025-12-12 HIGH 8.7 CVE-2024-58310 APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manip… No fix yet Fix from $1,9502025-12-11 HIGH 7.5 CVE-2024-58312 xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL par… Xbtitfm No fix yet Fix from $1,9502025-12-11 HIGH 8.8 CVE-2025-66429 An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitra… Cpanel 126.0.37 / 130.0.16+ Fix from $1,9502025-12-11 MEDIUM 6.5 CVE-2025-14293 The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUpload… Mitigation only Fix from $1,6002025-12-11 HIGH 7.5 CVE-2025-67742 In JetBrains TeamCity before 2025.11 path traversal was possible via file upload Teamcity 2025.11+ Fix from $1,9502025-12-11 CRITICAL 9.1 CVE-2025-14520 A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/inde… Hfly after 2016-05-11 Fix from $2,3002025-12-11 HIGH 7.5 CVE-2025-14521 A security vulnerability has been detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected element is an unknown function… Hfly after 2016-05-11 Fix from $1,9502025-12-11 MEDIUM 6.5 CVE-2025-67720 Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messa… Patch available Fix from $1,6002025-12-11 CRITICAL 9.1 CVE-2020-36898 QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers t… Qihang Media Web Digital Signage No fix yet Fix from $2,3002025-12-10 HIGH 7.5 CVE-2020-36893 Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files … I Media Server Digital Signage No fix yet Fix from $1,9502025-12-10 HIGH 8.1 CVE-2020-36883 SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backu… Fusion Digital Signage after 3.4.8 Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-56430 Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-… Fearlesscms No fix yet Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-56431 Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-… Fearlesscms No fix yet Fix from $1,9502025-12-10 MEDIUM 6.5 CVE-2025-65814 A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory trav… Office App Edit Word\, Pdf File No fix yet Fix from $1,6002025-12-10 MEDIUM 6.5 CVE-2025-65815 A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory tr… Document Reader\ No fix yet Fix from $1,6002025-12-10 CRITICAL 9.1 CVE-2025-65792 DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. Datagear No fix yet Fix from $2,3002025-12-10