Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.2 CVE-2025-13645 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_fi… Modula Image Gallery 2.13.3+ Fix from $1,9502025-12-03 MEDIUM 6.3 CVE-2025-13875 A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocih… Mitigation only Fix from $1,6002025-12-02 HIGH 7.8 CVE-2025-13876 A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the co… Hd Video Player All Formats No fix yet Fix from $1,9502025-12-02 CRITICAL 9.1 CVE-2025-66410 Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causi… Gin Vue Admin after 2.8.6 Fix from $2,3002025-12-01 HIGH 8.5 CVE-2025-66300 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "… Grav 1.8.0+ Fix from $1,9502025-12-01 MEDIUM 6.8 CVE-2025-66302 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated att… Grav 1.8.0+ Fix from $1,6002025-12-01 HIGH 8.8 CVE-2025-66295 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and su… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 8.6 CVE-2025-66206 Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein s… Frappe 14.99.2 / 15.86.0+ Fix from $1,9502025-12-01 HIGH 7.5 CVE-2025-65838 PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method. Publiccms No fix yet Fix from $1,9502025-12-01 HIGH 7.1 CVE-2025-63365 SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file processing component, specifically … Epub File Reader Mitigation only Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-13816 A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file… Mogublog after 5.2 Fix from $1,9502025-12-01 HIGH 7.5 CVE-2025-13810 A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java/com/jsnjfz/manage/modular/sy… Webstack Guns No fix yet Fix from $1,9502025-12-01 MEDIUM 6.5 CVE-2025-13791 A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProje… Scada Lts after 2.7.8.1 Fix from $1,6002025-11-30 HIGH 8.0 CVE-2025-12638 Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerabi… Mitigation only Fix from $1,9502025-11-28 HIGH 7.3 CVE-2025-59890 Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an atta… Mitigation only Fix from $1,9502025-11-27 CRITICAL 9.8 CVE-2025-66262 Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300… Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.1 CVE-2025-66251 Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30… Mozart Next 100 Firmware No fix yet Fix from $2,3002025-11-26 HIGH 8.7 CVE-2025-65952 Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability e… Patch available Fix from $1,9502025-11-25 HIGH 8.7 CVE-2025-34350 UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoi… Mitigation only Fix from $1,9502025-11-25 MEDIUM 6.9 CVE-2025-59372 A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to wri… Mitigation only Fix from $1,6002025-11-25 CRITICAL 9.2 CVE-2025-59366EPSS 16% An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality… Mitigation only Fix from $2,3002025-11-25 HIGH 8.2 CVE-2025-12003 A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device.… Mitigation only Fix from $1,9502025-11-25 CRITICAL 9.9 CVE-2025-54347 A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attack… Pingalert Application Server 6.1.1.6+ Fix from $2,3002025-11-24 HIGH 8.1 CVE-2025-60915 An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a pat… Openatlas after 8.12.0 Fix from $1,9502025-11-24 MEDIUM 5.3 CVE-2025-12972 Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses un… Fluent Bit Mitigation only Fix from $1,6002025-11-24 MEDIUM 5.5 CVE-2025-31248 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sono… macOS 13.7.3 / 14.7.3+ Fix from $1,6002025-11-21 CRITICAL 9.3 CVE-2025-34320 BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allow… Mitigation only Fix from $2,3002025-11-20 HIGH 8.1 CVE-2025-13435 A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/sr… Resty after 1.3.1 Fix from $1,9502025-11-20 HIGH 7.8 CVE-2025-11001EPSS 27% 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code … 7 Zip Mitigation only Fix from $1,9502025-11-19 HIGH 7.5 CVE-2025-63371 Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specific… Onecommander Mitigation only Fix from $1,9502025-11-19