Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2025-54387 IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used t… Ipx 1.3.2 / 2.1.1+ Fix from $2,3002025-08-05 CRITICAL 9.1 CVE-2025-54794 Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, … Claude Code 0.2.111+ Fix from $2,3002025-08-05 MEDIUM 5.0 CVE-2025-8522 A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of … Vvvebjs after 2.0.4 Fix from $1,6002025-08-04 MEDIUM 5.3 CVE-2025-8516 A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFacto… Mitigation only Fix from $1,6002025-08-04 HIGH 7.5 CVE-2025-7694 The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_d… Woffice 5.4.27+ Fix from $1,9502025-08-02 CRITICAL 9.8 CVE-2025-54386 Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability … Traefik 2.11.7 / 3.4.4+ Fix from $2,3002025-08-02 MEDIUM 6.9 CVE-2013-10062 A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05)… No fix yet Fix from $1,6002025-08-01 MEDIUM 6.9 CVE-2013-10063 A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded web server. Authenticated atta… No fix yet Fix from $1,6002025-08-01 HIGH 8.5 CVE-2013-10046 A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code… No fix yet Fix from $1,9502025-08-01 HIGH 8.0 CVE-2025-8480 Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected in… Ilx 507 Firmware Mitigation only Fix from $1,9502025-08-01 MEDIUM 5.4 CVE-2025-8433 A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the f… Document Management System No fix yet Fix from $1,6002025-08-01 CRITICAL 9.4 CVE-2025-8426 Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allow… Qconvergeconsole Mitigation only Fix from $2,3002025-07-31 HIGH 8.8 CVE-2014-125125 A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the han… No fix yet Fix from $1,9502025-07-31 HIGH 7.2 CVE-2025-46359 A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by r… Powercms 4.61 / 5.31+ Fix from $1,9502025-07-31 MEDIUM 6.5 CVE-2025-41396 A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product user. Powercms 4.61 / 5.31+ Fix from $1,6002025-07-31 CRITICAL 9.8 CVE-2025-8343 A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the… Shio after 0.3.8 Fix from $2,3002025-07-31 HIGH 7.2 CVE-2025-54433 Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ing… Patch available Fix from $1,9502025-07-30 HIGH 7.8 CVE-2025-43196 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A… macOS 13.7.7 / 14.7.7+ Fix from $1,9502025-07-30 MEDIUM 6.2 CVE-2025-43191 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A… macOS 13.7.7 / 14.7.7+ Fix from $1,6002025-07-30 HIGH 8.2 CVE-2025-44137 MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles … Tileserver Php Patch available Fix from $1,9502025-07-29 CRITICAL 9.1 CVE-2025-53081 An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesys… Data Management Server Firmware 2.3.13.1 / 2.6.14.1+ Fix from $2,3002025-07-29 MEDIUM 6.5 CVE-2025-53080 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers … Data Management Server Firmware 2.3.13.1 / 2.6.14.1+ Fix from $1,6002025-07-29 HIGH 8.1 CVE-2025-6989 The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in … Mitigation only Fix from $1,9502025-07-26 HIGH 8.5 CVE-2025-52452 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc a… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 MEDIUM 5.4 CVE-2025-8132 A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function delfile of the f… Chancms 3.1.3+ Fix from $1,6002025-07-25 HIGH 8.1 CVE-2025-7640 The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to… Mitigation only Fix from $1,9502025-07-24 HIGH 8.7 CVE-2018-25113 An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. The vulnerability allows remot… No fix yet Fix from $1,9502025-07-23 HIGH 8.7 CVE-2010-10012 A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbi… No fix yet Fix from $1,9502025-07-23 CRITICAL 9.8 CVE-2025-54450 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54453 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23