Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2025-31359 A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vuln… Parallels Desktop No fix yet Fix from $1,9502025-06-03 MEDIUM 5.3 CVE-2025-41428 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON f… Mitigation only Fix from $1,6002025-06-03 HIGH 8.7 CVE-2025-48387 tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the s… Patch available Fix from $1,9502025-06-02 HIGH 7.5 CVE-2025-27956 Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter. Weblaudos No fix yet Fix from $1,9502025-06-02 HIGH 7.2 CVE-2025-48940 MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attac… Mybb 1.8.39+ Fix from $1,9502025-06-02 CRITICAL 9.8 CVE-2025-37095 A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.1 CVE-2025-37094 A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 HIGH 7.5 CVE-2025-48957 AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead… Astrbot 3.5.13+ Fix from $1,9502025-06-02 MEDIUM 6.5 CVE-2025-33004 IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction. Planning Analytics Local Mitigation only Fix from $1,6002025-06-01 CRITICAL 9.8 CVE-2025-5385 A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgfo… Jeewms after 2025-05-04 Fix from $2,3002025-05-31 HIGH 7.2 CVE-2025-5381 A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/Fil… Yifang after 2.0.2 Fix from $1,9502025-05-31 MEDIUM 6.3 CVE-2025-5380 A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f… Mitigation only Fix from $1,6002025-05-31 HIGH 7.2 CVE-2025-4857 The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. Th… Newsletters 4.10+ Fix from $1,9502025-05-31 CRITICAL 9.1 CVE-2025-47952 Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in T… Traefik 2.11.25 / 3.4.1+ Fix from $2,3002025-05-30 HIGH 8.8 CVE-2025-5328 A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sy… Mccms No fix yet Fix from $1,9502025-05-29 HIGH 7.5 CVE-2024-51453 IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a speci… Sterling Secure Proxy after 6.2.0.1 Fix from $1,9502025-05-28 CRITICAL 9.8 CVE-2025-48744 In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution. Pmb 8.0.1.2+ Fix from $2,3002025-05-27 HIGH 7.5 CVE-2025-5161 A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function oper… Seccenter Smp 1114p02 after 20250513 Fix from $1,9502025-05-26 HIGH 7.5 CVE-2025-5159 A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of… Seccenter Smp 1114p02 after 20250513 Fix from $1,9502025-05-26 HIGH 7.5 CVE-2025-5160 A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the function Download of the file … Seccenter Smp 1114p02 after 20250513 Fix from $1,9502025-05-26 HIGH 7.5 CVE-2025-5158 A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function … Seccenter Smp 1114p02 after 20250513 Fix from $1,9502025-05-25 HIGH 7.5 CVE-2025-5157 A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of … Seccenter Smp 1114p02 after 20250513 Fix from $1,9502025-05-25 HIGH 7.5 CVE-2025-48273 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path T… Wp Job Portal 2.3.3+ Fix from $1,9502025-05-23 HIGH 7.5 CVE-2025-47603 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo belingogeo allows Path Traversal.T… Mitigation only Fix from $1,9502025-05-23 HIGH 8.6 CVE-2025-47535 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-cus… Mitigation only Fix from $1,9502025-05-23 HIGH 8.6 CVE-2025-47492 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor F… Mitigation only Fix from $1,9502025-05-23 HIGH 8.6 CVE-2025-47512 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainacan allows Path Traversal.This… Mitigation only Fix from $1,9502025-05-23 MEDIUM 6.5 CVE-2025-46527 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likecoin allows Path Traversal.Thi… Mitigation only Fix from $1,6002025-05-23 HIGH 7.7 CVE-2025-31053 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-… Mitigation only Fix from $1,9502025-05-23 HIGH 7.5 CVE-2025-3884 Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in… Hue Mitigation only Fix from $1,9502025-05-22