Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2025-2158 The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all ve… Mitigation only Fix from $1,9502025-05-10 MEDIUM 5.9 CVE-2025-3897 The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' fun… Mitigation only Fix from $1,6002025-05-09 HIGH 7.2 CVE-2025-4206 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deleti… Mitigation only Fix from $1,9502025-05-09 HIGH 8.3 CVE-2025-4377 Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.… Mitigation only Fix from $1,9502025-05-09 HIGH 7.5 CVE-2024-6648 Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_it… Ap Pagebuilder 4.0.0+ Fix from $1,9502025-05-08 HIGH 8.8 CVE-2025-32820 A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo… Sma 100 Firmware 10.2.1.15-81sv+ Fix from $1,9502025-05-07 MEDIUM 6.5 CVE-2025-20187 A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remo… Catalyst Sd Wan Manager Mitigation only Fix from $1,6002025-05-07 CRITICAL 9.1 CVE-2025-20949 Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Sa… Members 5.0.00.11+ Fix from $2,3002025-05-07 HIGH 7.5 CVE-2025-46559 Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api`… Misskey 2025.4.1+ Fix from $1,9502025-05-05 CRITICAL 9.1 CVE-2025-45238 foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method. Foxcms No fix yet Fix from $2,3002025-05-05 MEDIUM 5.3 CVE-2025-45239 An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal. Foxcms No fix yet Fix from $1,6002025-05-05 MEDIUM 5.3 CVE-2024-11615 The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLangu… Mitigation only Fix from $1,6002025-05-05 MEDIUM 5.3 CVE-2024-55913 IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craf… Concert 1.1.0+ Fix from $1,6002025-05-02 MEDIUM 6.3 CVE-2025-4185EPSS 11% A vulnerability, which was classified as critical, has been found in Wangshen SecGate 3600 2024. This issue affects some unknown processing of the fi… Mitigation only Fix from $1,6002025-05-02 MEDIUM 6.3 CVE-2025-4186 A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown function of the file /?g=route_isp… Mitigation only Fix from $1,6002025-05-02 MEDIUM 5.4 CVE-2025-4178 A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and classified as critical. This issue… Java Server after 2019-09-22 Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-4175 A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uplo… No fix yet Fix from $1,6002025-05-01 MEDIUM 5.3 CVE-2025-46565 Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project … Vite 4.5.14 / 5.4.19+ Fix from $1,6002025-05-01 HIGH 7.5 CVE-2025-27409 Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version … Joplin 3.3.3+ Fix from $1,9502025-04-30 HIGH 8.8 CVE-2025-2817 Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking be… Firefox 115.23.0 / 128.10.0+ Fix from $1,9502025-04-29 HIGH 8.1 CVE-2025-26692 Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited,… Mitigation only Fix from $1,9502025-04-28 MEDIUM 6.5 CVE-2025-27937 Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited,… Mitigation only Fix from $1,6002025-04-28 CRITICAL 9.8 CVE-2025-46433 In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible Teamcity 2025.03.1+ Fix from $2,3002025-04-25 MEDIUM 6.5 CVE-2025-28354 An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a cra… Mitigation only Fix from $1,6002025-04-25 HIGH 7.5 CVE-2025-1565 The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/pea… Mitigation only Fix from $1,9502025-04-25 HIGH 7.2 CVE-2025-3300 The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2… Mitigation only Fix from $1,9502025-04-24 CRITICAL 9.1 CVE-2025-3065 The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, an… Mitigation only Fix from $2,3002025-04-24 MEDIUM 6.5 CVE-2025-32950 Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, att… Jmix Framework 1.6.2 / 2.4.0+ Fix from $1,6002025-04-22 CRITICAL 10.0 CVE-2025-34028 KEVEPSS 98% The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand… Commvault 11.38.20+ Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-23250 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arb… Nemo 25.02+ Fix from $2,3002025-04-22