Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.3 CVE-2025-22240 Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated inp… Mitigation only Fix from $1,6002025-06-13 MEDIUM 5.6 CVE-2025-22241 File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki… Mitigation only Fix from $1,6002025-06-13 HIGH 8.8 CVE-2025-4613 Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b… Web Designer 16.3.0.0407+ Fix from $1,9502025-06-12 MEDIUM 6.1 CVE-2025-40592 A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Stu… Mitigation only Fix from $1,6002025-06-12 HIGH 7.8 CVE-2025-47176 '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502025-06-10 MEDIUM 5.4 CVE-2024-57189 In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCrea… Erxes 1.6.2+ Fix from $1,6002025-06-10 MEDIUM 5.4 CVE-2024-57186 In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint… Erxes 1.6.2+ Fix from $1,6002025-06-10 HIGH 7.7 CVE-2025-37100 A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successf… Mitigation only Fix from $1,9502025-06-10 HIGH 7.2 CVE-2025-5740 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes wh… Mitigation only Fix from $1,9502025-06-10 HIGH 7.6 CVE-2025-42977 SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privil… Mitigation only Fix from $1,9502025-06-10 MEDIUM 6.5 CVE-2025-49138 HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) … Haxcms Php 11.0.0+ Fix from $1,6002025-06-09 CRITICAL 9.1 CVE-2025-48267 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue … Wp Pipes 1.4.3+ Fix from $2,3002025-06-09 HIGH 7.5 CVE-2025-48130 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks spice-blocks allows Path Tra… Mitigation only Fix from $1,9502025-06-09 HIGH 7.5 CVE-2025-48124 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooC… Mitigation only Fix from $1,9502025-06-09 MEDIUM 6.5 CVE-2025-47511 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Pat… Welcart E Commerce 2.11.14+ Fix from $1,6002025-06-09 HIGH 8.1 CVE-2025-39473 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebGeniusLab Seofy Core seofy-core allows PHP Local F… Mitigation only Fix from $1,9502025-06-09 HIGH 7.5 CVE-2025-31635 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup CLEVER lbg-audio11-html5-shoutcast_histo… Mitigation only Fix from $1,9502025-06-09 HIGH 7.5 CVE-2025-31050 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appthaplugins Apptha Slider Gallery apptha-slider-gal… Mitigation only Fix from $1,9502025-06-09 HIGH 8.8 CVE-2025-3485 Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… Allegra 8.1.2+ Fix from $1,9502025-06-06 MEDIUM 6.5 CVE-2025-33035 A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vuln… File Station 5.5.6.4847+ Fix from $1,6002025-06-06 HIGH 8.1 CVE-2025-3055 The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_… Mitigation only Fix from $1,9502025-06-05 MEDIUM 6.7 CVE-2025-20277 A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on … Unified Contact Center Express Mitigation only Fix from $1,6002025-06-04 MEDIUM 5.3 CVE-2025-20259 Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delet… Thousandeyes Endpoint Agent 2.3.3+ Fix from $1,6002025-06-04 HIGH 7.5 CVE-2025-5545 A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the fun… Oa System No fix yet Fix from $1,9502025-06-04 HIGH 7.5 CVE-2025-5544 A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this … Oa System No fix yet Fix from $1,9502025-06-03 CRITICAL 9.8 CVE-2025-5509 A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload… Shiyi Blog after 1.2.1 Fix from $2,3002025-06-03 MEDIUM 5.3 CVE-2024-12718 Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extrac… Patch available Fix from $1,6002025-06-03 HIGH 7.5 CVE-2025-4138 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me… Patch available Fix from $1,9502025-06-03 HIGH 7.5 CVE-2025-4330 Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me… Patch available Fix from $1,9502025-06-03 CRITICAL 9.4 CVE-2025-4517 Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if… Patch available Fix from $2,3002025-06-03