Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2025-29420 PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function. Perfreeblog No fix yet Fix from $1,9502025-08-25 CRITICAL 9.4 CVE-2025-53120EPSS 9% A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s config… Mitigation only Fix from $2,3002025-08-25 MEDIUM 6.5 CVE-2025-9409 A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUpload of the file modules/system… Ruoyi Go after 2.1 Fix from $1,6002025-08-25 MEDIUM 6.5 CVE-2025-8562 The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.4.0 via the 'lens' parameter.… Patch available Fix from $1,6002025-08-25 CRITICAL 10.0 CVE-2025-9118 A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in o… Mitigation only Fix from $2,3002025-08-25 MEDIUM 6.5 CVE-2025-52450 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc ap… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,6002025-08-22 HIGH 7.8 CVE-2024-56179 In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victims' machines via directory tra… Mitigation only Fix from $1,9502025-08-22 HIGH 8.7 CVE-2010-20109 Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversa… No fix yet Fix from $1,9502025-08-21 MEDIUM 6.0 CVE-2025-57753 vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The … Mitigation only Fix from $1,6002025-08-21 CRITICAL 9.8 CVE-2025-8895 The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and… Mitigation only Fix from $2,3002025-08-21 MEDIUM 5.3 CVE-2025-53505 Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is… Group Office 6.8.119 / 25.0.20+ Fix from $1,6002025-08-21 HIGH 8.7 CVE-2012-10061 Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files… No fix yet Fix from $1,9502025-08-20 HIGH 7.5 CVE-2025-36114 IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall… Soar Qradar Plugin App after 5.6.0 Fix from $1,9502025-08-20 HIGH 7.2 CVE-2025-54926 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution wh… Mitigation only Fix from $1,9502025-08-20 HIGH 7.5 CVE-2025-54021 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list all… Mitigation only Fix from $1,9502025-08-20 HIGH 8.6 CVE-2025-48158 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field b… Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-47650 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path … Mitigation only Fix from $1,6002025-08-20 HIGH 8.8 CVE-2025-8141 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the dele… Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.8 CVE-2024-44373 A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code e… Mitigation only Fix from $2,3002025-08-19 MEDIUM 6.5 CVE-2025-55295 qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability exists in qbit_manage's web AP… Mitigation only Fix from $1,6002025-08-19 MEDIUM 6.9 CVE-2025-55214 Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe to generate a project from a s… Patch available Fix from $1,6002025-08-18 HIGH 7.2 CVE-2025-55282 aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to … Aiven Db Migrate 1.0.7+ Fix from $1,9502025-08-18 HIGH 8.5 CVE-2025-55201 Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write arbitrary files because Copi… Patch available Fix from $1,9502025-08-18 MEDIUM 5.9 CVE-2025-41242 Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An appli… No fix yet Fix from $1,6002025-08-18 HIGH 8.8 CVE-2025-3671 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 v… Mitigation only Fix from $1,9502025-08-16 HIGH 7.5 CVE-2025-7641 The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the … Mitigation only Fix from $1,9502025-08-15 CRITICAL 9.2 CVE-2025-34154 UnForm Server Manager versions prior to 10.1.12 expose an unauthenticated file read vulnerability via its log file analysis interface. The flaw resid… Mitigation only Fix from $2,3002025-08-13 CRITICAL 9.8 CVE-2012-10054 Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes … Umbraco Cms 4.7.1+ Fix from $2,3002025-08-13 CRITICAL 9.4 CVE-2011-10010 QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authe… No fix yet Fix from $2,3002025-08-13 HIGH 8.7 CVE-2011-10009 S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers t… No fix yet Fix from $1,9502025-08-13