Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2025-65025 esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path trav… Esm.sh 136+ Fix from $2,3002025-11-19 MEDIUM 5.3 CVE-2025-64765 Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the app… Astro 5.15.8+ Fix from $1,6002025-11-19 HIGH 7.8 CVE-2025-63408 Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive… Agent Dvr after 6.6.7.0 Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-41736 A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resu… Ewio2 M Firmware 2.2.0+ Fix from $1,9502025-11-18 CRITICAL 9.1 CVE-2025-40549 A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability t… Serv U 15.5.3+ Fix from $2,3002025-11-18 MEDIUM 6.2 CVE-2025-63918 PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files t… Pdfpatcher 1.1.3.4663+ Fix from $1,6002025-11-17 MEDIUM 5.3 CVE-2025-13266 A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the file vlife-base/src/main/java/… Mitigation only Fix from $1,6002025-11-17 CRITICAL 9.1 CVE-2025-13265 A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/ls… Lsfusion Platform after 6.1 Fix from $2,3002025-11-17 CRITICAL 9.8 CVE-2025-13262 A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file pl… Lsfusion Platform after 6.1 Fix from $2,3002025-11-17 MEDIUM 5.3 CVE-2025-13261 A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/ls… Lsfusion Platform after 6.1 Fix from $1,6002025-11-17 MEDIUM 6.3 CVE-2025-13246 A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthe… Mitigation only Fix from $1,6002025-11-16 HIGH 8.6 CVE-2025-63680 Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fall… Backitup after 2025 Fix from $1,9502025-11-14 CRITICAL 9.1 CVE-2025-36236 IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse … Vios Mitigation only Fix from $2,3002025-11-13 MEDIUM 6.5 CVE-2025-12089 The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the … Mitigation only Fix from $1,6002025-11-13 HIGH 8.7 CVE-2022-4982 DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes han… No fix yet Fix from $1,9502025-11-12 HIGH 8.7 CVE-2023-7327 Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation allows an unauthenticated att… No fix yet Fix from $1,9502025-11-12 HIGH 8.7 CVE-2016-15055 JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the … No fix yet Fix from $1,9502025-11-12 HIGH 8.7 CVE-2021-4463 Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' e… No fix yet Fix from $1,9502025-11-12 CRITICAL 9.8 CVE-2025-11366 N-central < 2025.4 is vulnerable to authentication bypass via path traversal N Central 2025.4+ Fix from $2,3002025-11-12 HIGH 7.3 CVE-2025-11565 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated system access w… Mitigation only Fix from $1,9502025-11-12 HIGH 8.8 CVE-2025-12382 Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to uploa… Firewall Analyzer Mitigation only Fix from $1,9502025-11-12 MEDIUM 6.8 CVE-2025-62449 Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized atta… Github Copilot Chat 0.32.0+ Fix from $1,6002025-11-11 MEDIUM 6.5 CVE-2025-60722 Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privi… Onedrive 7.42+ Fix from $1,6002025-11-11 HIGH 8.9 CVE-2025-11696 A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any… Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.8 CVE-2025-42894 Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write… Business Connector Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-42919 Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated UR… Mitigation only Fix from $1,6002025-11-11 HIGH 8.7 CVE-2018-25124 PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer comp… No fix yet Fix from $1,9502025-11-10 HIGH 8.8 CVE-2025-12922 A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm … Openclinica Mitigation only Fix from $1,9502025-11-10 MEDIUM 6.5 CVE-2025-12092 The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality … Patch available Fix from $1,6002025-11-08 MEDIUM 6.5 CVE-2025-12000 The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() functi… Mitigation only Fix from $1,6002025-11-08