Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2025-10468 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal. This … Mitigation only Fix from $1,9502025-09-19 CRITICAL 9.8 CVE-2025-59352 Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send… Dragonfly 2.1.0+ Fix from $2,3002025-09-17 CRITICAL 9.8 CVE-2025-59304 A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted… Swetrix after 4.0.0 Fix from $2,3002025-09-17 MEDIUM 6.5 CVE-2025-35430 CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated att… Thorium 1.1.2+ Fix from $1,6002025-09-17 MEDIUM 6.5 CVE-2025-9215 The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path … Mitigation only Fix from $1,6002025-09-17 MEDIUM 6.6 CVE-2025-10050 The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the… Mitigation only Fix from $1,6002025-09-17 HIGH 7.5 CVE-2025-34185 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote atta… Eve X1 Server Firmware after 4.7.18.0 Fix from $1,9502025-09-16 MEDIUM 6.9 CVE-2025-59336 Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix… Patch available Fix from $1,6002025-09-16 MEDIUM 5.5 CVE-2025-43314 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sono… macOS 14.8 / 15.7+ Fix from $1,6002025-09-15 MEDIUM 5.5 CVE-2025-43190 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Se… Ipados 14.8 / 15.7+ Fix from $1,6002025-09-15 HIGH 7.5 CVE-2025-59056 FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web… Freepbx 15.0.38 / 16.0.41+ Fix from $1,9502025-09-15 HIGH 7.5 CVE-2025-10472 A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the fi… Moneyprinterturbo after 1.2.6 Fix from $1,9502025-09-15 MEDIUM 6.3 CVE-2025-49089 wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd. Moneyprinterturbo Mitigation only Fix from $1,6002025-09-15 HIGH 7.2 CVE-2025-10176 The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t… Mitigation only Fix from $1,9502025-09-12 MEDIUM 5.3 CVE-2025-10273 A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such man… 10oa No fix yet Fix from $1,6002025-09-12 CRITICAL 10.0 CVE-2025-58321 Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. Dialink 1.8.0.0+ Fix from $2,3002025-09-11 HIGH 7.3 CVE-2025-58320EPSS 14% Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. Dialink 1.8.0.0+ Fix from $1,9502025-09-11 HIGH 8.7 CVE-2025-9918 A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions)… Mitigation only Fix from $1,9502025-09-11 HIGH 8.0 CVE-2025-9693 The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil… Mitigation only Fix from $1,9502025-09-11 HIGH 7.5 CVE-2025-10236 A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_f… Gpt Academic after 3.91 Fix from $1,9502025-09-11 MEDIUM 5.4 CVE-2025-10232 A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the file plugin/filemanager/controll… Mitigation only Fix from $1,6002025-09-10 HIGH 7.5 CVE-2025-59049 Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach … Patch available Fix from $1,9502025-09-10 MEDIUM 5.6 CVE-2025-29592 oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. Oa System No fix yet Fix from $1,6002025-09-10 HIGH 8.8 CVE-2025-41714 The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can ca… Mitigation only Fix from $1,9502025-09-10 CRITICAL 9.8 CVE-2025-23343 The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulner… Nvdebug 1.7.0+ Fix from $2,3002025-09-09 MEDIUM 6.8 CVE-2025-47415 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traver… Mitigation only Fix from $1,6002025-09-09 CRITICAL 10.0 CVE-2025-54261EPSS 21% ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traver… Coldfusion Mitigation only Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-58755 MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used direc… Medical Open Network For Ai after 1.5.0 Fix from $1,9502025-09-09 MEDIUM 5.3 CVE-2025-58751 Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu… Vite 5.4.20 / 6.3.6+ Fix from $1,6002025-09-08 CRITICAL 9.2 CVE-2025-5993 ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable para… Mitigation only Fix from $2,3002025-09-08