Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2025-42906 SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from ad… Mitigation only Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-9713EPSS 15% Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User int… Endpoint Manager 2024+ Fix from $1,9502025-10-13 CRITICAL 9.1 CVE-2025-11631 A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDo… Docsys after 2.02.36 Fix from $2,3002025-10-12 CRITICAL 9.8 CVE-2025-11630 A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component Fil… Docsys after 2.02.36 Fix from $2,3002025-10-12 HIGH 7.5 CVE-2025-61884 KEVEPSS 98% Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3… Configurator after 12.2.14 Fix from $1,9502025-10-12 HIGH 8.8 CVE-2025-11607 A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controll… Moneyprinterturbo after 1.2.6 Fix from $1,9502025-10-11 CRITICAL 9.8 CVE-2025-6439 The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrar… Mitigation only Fix from $2,3002025-10-11 HIGH 7.8 CVE-2025-21048 Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code. Android Mitigation only Fix from $1,9502025-10-10 MEDIUM 6.4 CVE-2025-35053 Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an aut… Project Center after 2024.3 Fix from $1,6002025-10-09 HIGH 8.8 CVE-2025-35055 Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writab… Project Center 2023.1+ Fix from $1,9502025-10-09 MEDIUM 5.0 CVE-2025-35056 Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the spec… Project Center 2024.1+ Fix from $1,6002025-10-09 HIGH 7.2 CVE-2025-34248 D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due t… Mitigation only Fix from $1,9502025-10-09 CRITICAL 9.6 CVE-2025-10284 BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting … Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.6 CVE-2025-10283 BBOT's gitdumper module could be abused to execute commands through a malicious git repository. Mitigation only Fix from $2,3002025-10-09 MEDIUM 6.5 CVE-2025-39664 Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define… Checkmk 2.2.0+ Fix from $1,6002025-10-09 CRITICAL 9.8 CVE-2025-7526 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due … Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.9 CVE-2025-61913EPSS 12% Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i… Flowise 3.0.8+ Fix from $2,3002025-10-08 HIGH 8.1 CVE-2025-61784 LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat A… Llama Factory 0.9.4+ Fix from $1,9502025-10-07 MEDIUM 6.0 CVE-2025-43934 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version… Data Domain Operating System 7.10.1.70 / 7.13.1.40+ Fix from $1,6002025-10-07 HIGH 7.5 CVE-2025-43889 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release Versions 7.1… Data Domain Operating System 7.10.1.70 / 7.13.1.40+ Fix from $1,9502025-10-07 HIGH 8.1 CVE-2025-40889 A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated u… Cmc 25.2.0+ Fix from $1,9502025-10-07 MEDIUM 5.4 CVE-2025-3718 A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. … Cmc 25.2.0+ Fix from $1,6002025-10-07 MEDIUM 5.7 CVE-2025-60969 Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sen… Sonoma D12 Firmware Mitigation only Fix from $1,6002025-10-06 MEDIUM 5.3 CVE-2025-11336 A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown… Mitigation only Fix from $1,6002025-10-06 MEDIUM 5.3 CVE-2025-11337 A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneRepor… Mitigation only Fix from $1,6002025-10-06 HIGH 7.5 CVE-2025-58591 A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerabl… Baggage Analytics Mitigation only Fix from $1,9502025-10-06 HIGH 7.5 CVE-2025-58590 It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information. Baggage Analytics after 4.6.1 Fix from $1,9502025-10-06 MEDIUM 5.8 CVE-2025-8917 A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extrac… Patch available Fix from $1,6002025-10-05 HIGH 7.8 CVE-2025-8406 ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_director… Zenml 0.84.2+ Fix from $1,9502025-10-05 MEDIUM 6.5 CVE-2025-33034 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 5.0.0.1+ Fix from $1,6002025-10-03