Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2025-64485 CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1, a malicious CVAT user with … Patch available Fix from $1,6002025-11-08 MEDIUM 6.5 CVE-2025-64433 KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arb… Kubevirt 1.5.3+ Fix from $1,6002025-11-07 HIGH 7.5 CVE-2025-60574 A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to prope… Tquadra Cms No fix yet Fix from $1,9502025-11-07 HIGH 7.5 CVE-2025-57698 AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-up… Astrbot No fix yet Fix from $1,9502025-11-07 MEDIUM 5.3 CVE-2025-7719 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File M… Mitigation only Fix from $1,6002025-11-07 MEDIUM 6.5 CVE-2025-57712 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 5.0.0.3+ Fix from $1,6002025-11-07 MEDIUM 6.0 CVE-2025-64346 archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to feed a specially crafted archiv… Patch available Fix from $1,6002025-11-07 HIGH 8.8 CVE-2025-64184 Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from di… Patch available Fix from $1,9502025-11-07 HIGH 8.8 CVE-2025-58423 Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse di… Deviceon\/iedge after 2.0.2 Fix from $1,9502025-11-06 CRITICAL 9.8 CVE-2025-59171 Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code exe… Deviceon\/iedge after 2.0.2 Fix from $2,3002025-11-06 CRITICAL 9.8 CVE-2025-62630 Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code exe… Deviceon\/iedge after 2.0.2 Fix from $2,3002025-11-06 MEDIUM 6.5 CVE-2025-34238 Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConf… Webaccess\/vpn 1.1.5+ Fix from $1,6002025-11-06 HIGH 8.8 CVE-2025-12490EPSS 20% Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files … Patch available Fix from $1,9502025-11-06 HIGH 7.5 CVE-2025-60242 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Anatoly Download Counter download-counter allows Path… Mitigation only Fix from $1,9502025-11-06 HIGH 8.8 CVE-2025-64107 Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects p… Cursor 2.0+ Fix from $1,9502025-11-04 HIGH 8.8 CVE-2025-64108 Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci… Cursor 2.0+ Fix from $1,9502025-11-04 CRITICAL 9.8 CVE-2025-12493 The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnera… Shoplentor 3.2.6+ Fix from $2,3002025-11-04 MEDIUM 5.5 CVE-2025-43382 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.2, macOS So… macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 HIGH 7.5 CVE-2025-50735 Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-al… Nextchat after 2.16.0 Fix from $1,9502025-11-03 HIGH 8.6 CVE-2025-10897 The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it pos… Mitigation only Fix from $1,9502025-10-31 MEDIUM 6.8 CVE-2025-8385 The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input valid… Mitigation only Fix from $1,6002025-10-31 HIGH 7.5 CVE-2025-3355 IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could … Tivoli Monitoring Mitigation only Fix from $1,9502025-10-30 CRITICAL 9.8 CVE-2025-3356 IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could … Tivoli Monitoring Mitigation only Fix from $2,3002025-10-30 HIGH 8.9 CVE-2025-12060 The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility… Patch available Fix from $1,9502025-10-30 CRITICAL 9.8 CVE-2025-11201EPSS 27% MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute … Mlflow 2025-06-10+ Fix from $2,3002025-10-29 CRITICAL 9.8 CVE-2025-12422 Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; B… Blu Ic2 Firmware 1.20+ Fix from $2,3002025-10-28 HIGH 8.9 CVE-2025-62725EPSS 14% Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends… Patch available Fix from $1,9502025-10-27 HIGH 8.6 CVE-2025-27222 TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't proper… Trufusion Enterprise after 7.10.4.0 Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-12055 HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance… Mitigation only Fix from $1,9502025-10-27 HIGH 8.1 CVE-2025-10488 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to i… Mitigation only Fix from $1,9502025-10-25