Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2025-6803 Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-6804 Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacke… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 CRITICAL 9.1 CVE-2025-6805 Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to … Qconvergeconsole Mitigation only Fix from $2,3002025-07-07 HIGH 7.5 CVE-2025-6806 Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arb… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-6807 Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to dis… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-6796 Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disc… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-6797 Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to d… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 CRITICAL 9.1 CVE-2025-6798 Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delet… Qconvergeconsole after 5.5.0.85 Fix from $2,3002025-07-07 HIGH 7.5 CVE-2025-6799 Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to d… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-6800 Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-6801 Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to cr… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 CRITICAL 9.4 CVE-2025-6793EPSS 12% Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability … Qconvergeconsole after 5.5.0.85 Fix from $2,3002025-07-07 CRITICAL 9.8 CVE-2025-6794 Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ar… Qconvergeconsole after 5.5.0.85 Fix from $2,3002025-07-07 HIGH 7.5 CVE-2025-6795 Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to di… Qconvergeconsole after 5.5.0.85 Fix from $1,9502025-07-07 HIGH 7.5 CVE-2023-51232 Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted reques… Patch available Fix from $1,9502025-07-07 MEDIUM 6.2 CVE-2025-6210 A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path … Llamaindex 0.5.2+ Fix from $1,6002025-07-07 HIGH 7.5 CVE-2025-3046 A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read th… Llamaindex 0.12.28+ Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-7107 A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/… Sim after 0.1.17 Fix from $1,9502025-07-07 MEDIUM 5.4 CVE-2025-7108 A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vulnerability is the function de… No fix yet Fix from $1,6002025-07-07 HIGH 8.8 CVE-2025-7098 A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the … Internet Security No fix yet Fix from $1,9502025-07-06 MEDIUM 6.8 CVE-2025-49303 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-fronte… Mitigation only Fix from $1,6002025-07-04 HIGH 7.7 CVE-2025-28980 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA aviation-weath… Mitigation only Fix from $1,9502025-07-04 HIGH 8.8 CVE-2025-2932 The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' func… Mitigation only Fix from $1,9502025-07-03 HIGH 7.2 CVE-2025-34076 An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the backup management API. Authenti… Microweber after 1.2.11 Fix from $1,9502025-07-02 MEDIUM 6.5 CVE-2025-53358 kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_f… Patch available Fix from $1,6002025-07-02 HIGH 7.3 CVE-2025-53110 Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6… Patch available Fix from $1,9502025-07-02 HIGH 8.1 CVE-2025-4946 The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_me… Mitigation only Fix from $1,9502025-07-02 MEDIUM 6.5 CVE-2025-27022 A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files… G42 Firmware 7.1+ Fix from $1,6002025-07-02 MEDIUM 6.4 CVE-2025-24329 Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) manag… Mitigation only Fix from $1,6002025-07-02 MEDIUM 6.4 CVE-2025-24330 Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) manage… Mitigation only Fix from $1,6002025-07-02