Vulnerability index

Browse CVEs

8,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2025-54443 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload … Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54446 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload … Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54438 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload … Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 HIGH 7.5 CVE-2025-8021 All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files… Mitigation only Fix from $1,9502025-07-23 HIGH 7.5 CVE-2025-54140 pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exi… Patch available Fix from $1,9502025-07-22 HIGH 7.5 CVE-2025-54141 ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the stan… Viewvc 1.1.31 / 1.2.4+ Fix from $1,9502025-07-22 MEDIUM 5.0 CVE-2025-51475 Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite ar… Superagi Patch available Fix from $1,6002025-07-22 MEDIUM 6.6 CVE-2025-51481 Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary fil… Dagster Patch available Fix from $1,6002025-07-22 HIGH 7.0 CVE-2025-51463 Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup… Aim Patch available Fix from $1,9502025-07-22 HIGH 8.8 CVE-2025-51480 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplyin… Onnx Patch available Fix from $1,9502025-07-22 HIGH 8.1 CVE-2025-7645 The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to arbitrary file deletion du… Mitigation only Fix from $1,9502025-07-22 CRITICAL 9.8 CVE-2025-46120 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, … Ruckus Unleashed 10.5.1.0.279 / 200.15.6.212.14+ Fix from $2,3002025-07-21 HIGH 7.5 CVE-2025-49656 Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to… Jena 5.5.0+ Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-7896 A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function … Moneyprinterturbo after 1.2.6 Fix from $1,9502025-07-20 HIGH 7.5 CVE-2015-10134 The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_fil… Simple Backup after 2.7.10 Fix from $1,9502025-07-19 HIGH 7.5 CVE-2015-10136 The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthe… Gi Media Library 3.0+ Fix from $1,9502025-07-19 HIGH 7.5 CVE-2025-27210EPSS 10% An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vul… Mitigation only Fix from $1,9502025-07-18 CRITICAL 9.1 CVE-2025-7643 The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions()… Mitigation only Fix from $2,3002025-07-18 HIGH 8.8 CVE-2025-3740 The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 vi… Mitigation only Fix from $1,9502025-07-18 CRITICAL 9.1 CVE-2025-7712 The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip()… Mitigation only Fix from $2,3002025-07-17 HIGH 8.7 CVE-2025-34126 A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system w… No fix yet Fix from $1,9502025-07-16 HIGH 8.7 CVE-2025-34118 A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unau… Mitigation only Fix from $1,9502025-07-16 HIGH 8.7 CVE-2025-34120 An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails … Mitigation only Fix from $1,9502025-07-16 HIGH 7.5 CVE-2025-31070 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Build… Mitigation only Fix from $1,9502025-07-16 HIGH 7.5 CVE-2025-28955 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce fw… Mitigation only Fix from $1,9502025-07-16 HIGH 8.2 CVE-2025-7359 The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t… Mitigation only Fix from $1,9502025-07-16 MEDIUM 6.5 CVE-2025-49830 Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the poli… Conjur 1.22.1 / 13.5.1+ Fix from $1,6002025-07-15 HIGH 7.1 CVE-2025-50819 Directory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing the the topi… Mitigation only Fix from $1,9502025-07-15 MEDIUM 5.2 CVE-2025-53622 DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a … Patch available Fix from $1,6002025-07-15 CRITICAL 9.3 CVE-2025-34110 A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbit… Patch available Fix from $2,3002025-07-15