Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2025-23304 NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loadin… Nemo 2.3.2+ Fix from $2,3002025-08-13 HIGH 7.8 CVE-2025-8941 A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks … Mitigation only Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-8912 Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit … Organization Portal System Mitigation only Fix from $1,9502025-08-13 MEDIUM 6.5 CVE-2025-8909 Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to … Organization Portal System Mitigation only Fix from $1,6002025-08-13 MEDIUM 6.5 CVE-2025-0818 Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible … Mitigation only Fix from $1,6002025-08-13 MEDIUM 6.5 CVE-2025-55169 WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul… Wegia 3.4.8+ Fix from $1,6002025-08-12 MEDIUM 6.5 CVE-2024-52964 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 throu… Fortimanager 7.0.14 / 7.2.10+ Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-53793 Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. Azure Stack Hub 1.2406.1.23 / 1.2408.1.50+ Fix from $1,9502025-08-12 MEDIUM 5.3 CVE-2025-49559 Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pat… Commerce 1.3.3 / 2.4.4+ Fix from $1,6002025-08-12 MEDIUM 5.3 CVE-2025-55011 Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does no… Kanboard 1.2.47+ Fix from $1,6002025-08-12 HIGH 8.1 CVE-2025-5391 The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_… Mitigation only Fix from $1,9502025-08-12 MEDIUM 6.9 CVE-2025-42946 Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific tr… Mitigation only Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-25231EPSS 20% Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive inform… Mitigation only Fix from $1,9502025-08-11 CRITICAL 9.8 CVE-2025-8815 A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown… Morning Mitigation only Fix from $2,3002025-08-10 MEDIUM 5.4 CVE-2025-8753 A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete o… Litemall after 1.8.0 Fix from $1,6002025-08-09 MEDIUM 6.7 CVE-2025-55149 Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and re… Mitigation only Fix from $1,6002025-08-09 HIGH 8.7 CVE-2012-10048 Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() … No fix yet Fix from $1,9502025-08-08 CRITICAL 9.8 CVE-2025-52913 A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker… Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.8 CVE-2025-8356EPSS 15% In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lea… Freeflow Core Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.1 CVE-2025-8729 A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is the function process_cert_file… Lmeterx Patch available Fix from $2,3002025-08-08 MEDIUM 6.5 CVE-2025-8749 Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR Robots allows authenticated us… Mitigation only Fix from $1,6002025-08-08 MEDIUM 6.5 CVE-2024-55401 An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal. Exonaut 21.6.2.1-1 / 22.4+ Fix from $1,6002025-08-07 HIGH 8.7 CVE-2025-29865 : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.T… Mitigation only Fix from $1,9502025-08-07 MEDIUM 5.4 CVE-2024-52885 The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (autho… Mobile Access Mitigation only Fix from $1,6002025-08-06 HIGH 7.1 CVE-2025-21015 Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege. Android Mitigation only Fix from $1,9502025-08-06 MEDIUM 6.5 CVE-2025-54653 Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the v… Harmonyos Mitigation only Fix from $1,6002025-08-06 MEDIUM 5.5 CVE-2025-54652 Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the v… Harmonyos No fix yet Fix from $1,6002025-08-06 HIGH 7.5 CVE-2012-10034 ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails … Clansphere No fix yet Fix from $1,9502025-08-05 HIGH 7.1 CVE-2012-10024 XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails … Patch available Fix from $1,9502025-08-05 CRITICAL 9.8 CVE-2025-54802 pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path tra… Pyload Ng Patch available Fix from $2,3002025-08-05