Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2025-34395 Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthentica… Rmm 2025.1.1+ Fix from $1,9502025-12-10 HIGH 8.8 CVE-2025-8110 KEVEPSS 83% Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. Gogs after 0.13.3 Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-13339 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the templa… Mitigation only Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-67506 PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/… Pipeshub Patch available Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2025-61811 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code… Coldfusion Mitigation only Fix from $2,3002025-12-10 HIGH 7.5 CVE-2025-66645 NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, w… Nicegui 3.4.0+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-67488 SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function impo… Siyuan 3.5.0+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2023-53772 MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET para… Minidvblinux after 5.4 Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2021-47724 STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files… Provision No fix yet Fix from $1,6002025-12-09 HIGH 8.8 CVE-2025-11531 HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential … Omen Gaming Hub 3.2.12 / 1101.2511.101.0+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-60024 Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoic… Fortivoice 7.0.8 / 7.2.3+ Fix from $1,9502025-12-09 MEDIUM 6.8 CVE-2025-14311 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects JMRI: before 5.13.3. Patch available Fix from $1,6002025-12-09 CRITICAL 9.1 CVE-2025-14306 A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly … Robocode Patch available Fix from $2,3002025-12-09 HIGH 8.0 CVE-2025-13661 Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of th… Endpoint Manager 2024+ Fix from $1,9502025-12-09 MEDIUM 6.6 CVE-2025-13070 The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include f… Mitigation only Fix from $1,6002025-12-09 CRITICAL 9.8 CVE-2025-14224 A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the componen… Dm2 Firmware after 1.9.12 Fix from $2,3002025-12-08 CRITICAL 9.8 CVE-2025-14182 A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the file /sobey-mchEditor/waterm… Media Convergence System Mitigation only Fix from $2,3002025-12-07 HIGH 8.1 CVE-2025-13377 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to i… 10web Booster 2.32.11+ Fix from $1,9502025-12-06 HIGH 8.1 CVE-2025-14111 A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarla… Rar after 7.11 Fix from $1,9502025-12-05 HIGH 8.1 CVE-2025-65879 Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-contr… Warehouse Management System after 1.2 Fix from $1,9502025-12-05 HIGH 7.5 CVE-2025-65878 The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize use… Warehouse Management System No fix yet Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-65897 zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file up… Zdh Web after 5.6.17 Fix from $1,9502025-12-05 HIGH 8.3 CVE-2025-64057 Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locatio… X210 Firmware No fix yet Fix from $1,9502025-12-05 MEDIUM 6.5 CVE-2016-20023 In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provid… Ckfinder 2.5.0.1+ Fix from $1,6002025-12-05 HIGH 7.8 CVE-2025-54160 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.… Beedrive 1.4.2-13960+ Fix from $1,9502025-12-04 HIGH 8.8 CVE-2025-54307 An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupd… Torrent Suite Software Mitigation only Fix from $1,9502025-12-04 CRITICAL 9.1 CVE-2025-65346 alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive con… Laravel File Manager after 3.3.1 Fix from $2,3002025-12-04 MEDIUM 5.4 CVE-2025-29843 A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. Router Manager 1.3.1-9346+ Fix from $1,6002025-12-04 HIGH 7.2 CVE-2025-29846 A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. Router Manager 1.3.1-9346+ Fix from $1,9502025-12-04 MEDIUM 6.5 CVE-2025-65345 alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create arc… Laravel File Manager after 3.3.1 Fix from $1,6002025-12-03