Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.7 CVE-2025-61666 Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between v… Mitigation only Fix from $1,9502025-10-02 HIGH 7.5 CVE-2025-59744 Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only within the web root using the “doc… E Tms Mitigation only Fix from $1,9502025-10-02 MEDIUM 6.5 CVE-2025-54293 Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on … Lxd 5.21.4 / 6.5+ Fix from $1,6002025-10-02 HIGH 8.8 CVE-2025-11221 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTON… Mitigation only Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-11020 An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of… Mitigation only Fix from $1,9502025-10-02 MEDIUM 6.5 CVE-2025-11182 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE Chang… Mitigation only Fix from $1,6002025-10-02 MEDIUM 6.3 CVE-2025-11233 Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle path separators, causing the … Patch available Fix from $1,6002025-10-01 MEDIUM 6.5 CVE-2025-8559 The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.1 via the 'theme' paramete… Mitigation only Fix from $1,6002025-09-30 MEDIUM 5.3 CVE-2025-61586 FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, a… Freshrss 1.27.0+ Fix from $1,6002025-09-30 HIGH 8.2 CVE-2025-43813 Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported vers… Digital Experience Platform 7.3 / 7.4.3.108+ Fix from $1,9502025-09-29 CRITICAL 9.8 CVE-2025-11139 A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.F… Zhiyou Erp after 11.0 Fix from $2,3002025-09-29 CRITICAL 9.8 CVE-2025-11079 A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation r… Farm Management System Mitigation only Fix from $2,3002025-09-27 MEDIUM 5.3 CVE-2025-11031 A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/resources/examples.php. This man… Datatables 1.10.15+ Fix from $1,6002025-09-26 HIGH 7.5 CVE-2025-11018 A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/..… Water Conservancy Informatization No fix yet Fix from $1,9502025-09-26 HIGH 7.7 CVE-2025-59002 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Tr… Mitigation only Fix from $1,9502025-09-26 MEDIUM 6.5 CVE-2025-10307 The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… Mitigation only Fix from $1,6002025-09-26 HIGH 7.3 CVE-2025-10951 A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vulnerability is the function log… Mitigation only Fix from $1,9502025-09-25 HIGH 8.6 CVE-2025-10449 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Por… Mitigation only Fix from $1,9502025-09-25 HIGH 8.7 CVE-2025-59343 tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the des… Patch available Fix from $1,9502025-09-24 HIGH 7.1 CVE-2025-56815 Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to… Datart No fix yet Fix from $1,9502025-09-24 HIGH 8.8 CVE-2025-56816 Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML … Datart No fix yet Fix from $1,9502025-09-24 MEDIUM 6.1 CVE-2025-59825 astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-tar, tar archives may extract… Patch available Fix from $1,6002025-09-23 CRITICAL 9.4 CVE-2025-9963 A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with root permissions. This way the… Mitigation only Fix from $2,3002025-09-23 MEDIUM 6.5 CVE-2025-57682 Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through … Papermark after 0.20.0 Fix from $1,6002025-09-22 MEDIUM 6.3 CVE-2025-10777 A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /downloadas/. Executing manipul… Mitigation only Fix from $1,6002025-09-22 HIGH 7.2 CVE-2025-9079 Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory pat… Mattermost Server 9.11.18 / 10.5.9+ Fix from $1,9502025-09-19 CRITICAL 9.1 CVE-2025-57644 Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe… Automation Platform Mitigation only Fix from $2,3002025-09-19 MEDIUM 5.3 CVE-2025-56869 Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via Files… Sync In Server after 1.1.1 Fix from $1,6002025-09-19 HIGH 7.5 CVE-2025-10708 A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this vulnerability is an unknown… Water Conservancy Informatization No fix yet Fix from $1,9502025-09-19 HIGH 7.5 CVE-2025-10709 A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is some unknown functionality of th… Water Conservancy Informatization No fix yet Fix from $1,9502025-09-19