Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.4 CVE-2025-58438 internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vu… Patch available Fix from $2,3002025-09-06 HIGH 8.1 CVE-2025-9566 There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a… Patch available Fix from $1,9502025-09-05 MEDIUM 5.5 CVE-2025-48550 In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead … Android Patch available Fix from $1,6002025-09-04 MEDIUM 6.5 CVE-2025-41035 A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to… Apprain Mitigation only Fix from $1,6002025-09-04 HIGH 7.7 CVE-2025-58355 Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with unc… Mitigation only Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-7975 Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb… Shockline 2025.4.2+ Fix from $1,9502025-09-02 MEDIUM 6.5 CVE-2025-58162 MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write … Mobile Security Framework Patch available Fix from $1,6002025-09-02 HIGH 8.1 CVE-2025-9801 A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manip… Sim 0.3.40+ Fix from $1,9502025-09-01 HIGH 7.0 CVE-2025-52861 A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account, they can then exploit the vu… Mitigation only Fix from $1,9502025-08-29 HIGH 8.8 CVE-2025-58158 Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact … Patch available Fix from $1,9502025-08-29 MEDIUM 6.5 CVE-2025-33033 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 4.5.0.7+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-33036 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 4.5.0.7+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-33037 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 4.5.0.7+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-33038 A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner… Qsync Central 4.5.0.7+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-30270 A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they ca… Qts Mitigation only Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-30271 A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they ca… Qts Mitigation only Fix from $1,6002025-08-29 MEDIUM 5.4 CVE-2025-9650 A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This affects the function removeFileByPath of the … Mitigation only Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-9217 The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_… Mitigation only Fix from $1,6002025-08-29 HIGH 8.8 CVE-2024-13986 Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Cor… Nagios Xi 2024+ Fix from $1,9502025-08-28 HIGH 7.7 CVE-2025-54029 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export extendons-eo-… Mitigation only Fix from $1,9502025-08-28 HIGH 7.7 CVE-2025-53588 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code G… Mitigation only Fix from $1,9502025-08-28 HIGH 7.5 CVE-2025-58072 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a a… Mitigation only Fix from $1,9502025-08-28 MEDIUM 6.5 CVE-2025-54819 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a a… Mitigation only Fix from $1,6002025-08-28 CRITICAL 10.0 CVE-2024-13981 LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerabil… Mitigation only Fix from $2,3002025-08-27 HIGH 8.7 CVE-2024-13982 SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerabili… Mitigation only Fix from $1,9502025-08-27 CRITICAL 10.0 CVE-2024-13984 QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows… Mitigation only Fix from $2,3002025-08-27 CRITICAL 10.0 CVE-2023-7309 A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated M… Mitigation only Fix from $2,3002025-08-27 HIGH 7.2 CVE-2025-20344 A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversa… Nexus Dashboard 4.1+ Fix from $1,9502025-08-27 HIGH 7.5 CVE-2025-50971 Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the templ… Abantecart No fix yet Fix from $1,9502025-08-26 CRITICAL 9.1 CVE-2025-55526 n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py N8n Workflow Collection No fix yet Fix from $2,3002025-08-26