Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2025-50349 PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php. Pre School Enrollment System No fix yet Fix from $1,9502025-06-23 HIGH 7.8 CVE-2025-6218 KEVEPSS 89% RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect… Winrar 7.12+ Fix from $1,9502025-06-21 CRITICAL 9.3 CVE-2025-34022 A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, T… No fix yet Fix from $2,3002025-06-20 HIGH 8.5 CVE-2025-34023 A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sani… No fix yet Fix from $1,9502025-06-20 CRITICAL 9.8 CVE-2025-45890 Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter Novel Plus 5.1.0+ Fix from $2,3002025-06-20 HIGH 7.5 CVE-2025-6283 A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the function GET of the file apps/dba… Agent 0.3.1+ Fix from $1,9502025-06-19 CRITICAL 9.8 CVE-2025-6280 A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachmen… Superagi after 0.0.14 Fix from $2,3002025-06-19 MEDIUM 6.3 CVE-2025-6281 A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality o… Xagent Mitigation only Fix from $1,6002025-06-19 CRITICAL 9.8 CVE-2025-6282 A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is… Openagents after 2024-11-18 Fix from $2,3002025-06-19 CRITICAL 9.8 CVE-2025-6278 A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/s… Upsonic after 0.55.6 Fix from $2,3002025-06-19 MEDIUM 6.5 CVE-2025-5981 Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for con… Osv Scalibr 0.1.8+ Fix from $1,6002025-06-18 HIGH 7.5 CVE-2025-50202 Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment vari… Patch available Fix from $1,9502025-06-18 HIGH 8.6 CVE-2025-49879 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho litho allows Path Traversal.This issue… Mitigation only Fix from $1,9502025-06-17 HIGH 8.6 CVE-2025-49415 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Path Travers… Mitigation only Fix from $1,9502025-06-17 MEDIUM 6.3 CVE-2025-34508EPSS 69% A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticate… Mitigation only Fix from $1,6002025-06-17 HIGH 7.8 CVE-2025-6020 A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to eleva… Mitigation only Fix from $1,9502025-06-17 CRITICAL 9.8 CVE-2025-6167 A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file p… Python A2a after 0.5.5 Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-6152 A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api… Browser Patch available Fix from $2,3002025-06-17 CRITICAL 9.8 CVE-2025-32799 Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path trav… Conda Build 25.4.0+ Fix from $2,3002025-06-16 CRITICAL 9.8 CVE-2025-3594 Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA… Digital Experience Platform after 7.4.3.4 Fix from $2,3002025-06-16 MEDIUM 6.3 CVE-2025-6108 A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Aff… No fix yet Fix from $1,6002025-06-16 MEDIUM 6.5 CVE-2025-5964EPSS 14% A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. M Files Server 24.8.13981.16 / 25.2.14524.9+ Fix from $1,6002025-06-15 CRITICAL 9.1 CVE-2025-6065 The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' t… Mitigation only Fix from $2,3002025-06-14 MEDIUM 6.5 CVE-2025-6070 The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() funct… Mitigation only Fix from $1,6002025-06-14 MEDIUM 5.9 CVE-2025-4187 The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ… Mitigation only Fix from $1,6002025-06-14 HIGH 7.5 CVE-2025-28382 An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Cosmos Patch available Fix from $1,9502025-06-13 CRITICAL 9.1 CVE-2025-28384 An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Cosmos Patch available Fix from $2,3002025-06-13 MEDIUM 6.1 CVE-2025-46096 Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component Solon No fix yet Fix from $1,6002025-06-13 CRITICAL 9.8 CVE-2025-46783 Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code… Mitigation only Fix from $2,3002025-06-13 HIGH 7.5 CVE-2024-38824 Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory. Salt 3006.12 / 3007.4+ Fix from $1,9502025-06-13