Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.0 CVE-2025-32018 Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of… Mitigation only Fix from $1,9502025-04-08 HIGH 7.2 CVE-2025-25254 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version… Fortiweb 7.4.7 / 7.6.3+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2024-41792 A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a path travers… 7kt Pac1260 Data Manager Firmware Mitigation only Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2025-2519 The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient fi… Mitigation only Fix from $1,6002025-04-08 CRITICAL 9.8 CVE-2025-3381 A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMControlle… Youkefu No fix yet Fix from $2,3002025-04-07 HIGH 7.7 CVE-2025-3424 The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through … Mitigation only Fix from $1,9502025-04-07 HIGH 7.5 CVE-2025-31174 Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos Mitigation only Fix from $1,9502025-04-07 MEDIUM 5.3 CVE-2025-3317 A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown fun… Opencms Mitigation only Fix from $1,6002025-04-06 CRITICAL 9.8 CVE-2025-2941 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path vali… Mitigation only Fix from $2,3002025-04-05 HIGH 8.1 CVE-2025-2270 The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… Mitigation only Fix from $1,9502025-04-04 MEDIUM 6.5 CVE-2025-31800 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in publitio Publitio publitio allows Path Traversal.This… Mitigation only Fix from $1,6002025-04-03 MEDIUM 5.9 CVE-2025-31554 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso docxpresso allows Absolute Path… Mitigation only Fix from $1,6002025-04-03 MEDIUM 6.5 CVE-2025-30596 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file include-file allows Path Trave… Mitigation only Fix from $1,6002025-04-03 CRITICAL 9.8 CVE-2025-22926 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna… Opensis after 9.1 Fix from $2,3002025-04-03 CRITICAL 9.1 CVE-2025-22927 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna… Opensis after 9.1 Fix from $2,3002025-04-03 HIGH 8.8 CVE-2025-22923 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /… Opensis after 9.1 Fix from $1,9502025-04-02 MEDIUM 6.7 CVE-2023-46988 Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt… Document Server 8.0.1+ Fix from $1,6002025-04-01 CRITICAL 9.9 CVE-2025-30841 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows … Mitigation only Fix from $2,3002025-04-01 HIGH 7.5 CVE-2025-31131EPSS 5% YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on … Yeswiki 4.5.2+ Fix from $1,9502025-04-01 HIGH 7.5 CVE-2025-30882 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Tr… Js Help Desk 2.9.2+ Fix from $1,9502025-04-01 HIGH 8.6 CVE-2025-30910 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager cm-downloa… Mitigation only Fix from $1,9502025-04-01 CRITICAL 9.1 CVE-2025-30878 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Tr… Js Help Desk 2.9.3+ Fix from $2,3002025-04-01 HIGH 7.5 CVE-2025-30793 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-fe… Mitigation only Fix from $1,9502025-04-01 MEDIUM 6.5 CVE-2025-30594 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in samsk Include URL include-url allows Path Traversal.T… Mitigation only Fix from $1,6002025-04-01 MEDIUM 5.3 CVE-2025-3043 A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the function preHandle of the fil… Mitigation only Fix from $1,6002025-04-01 MEDIUM 5.5 CVE-2025-30470 A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, ma… Ipados 2.4 / 13.7.5+ Fix from $1,6002025-03-31 HIGH 8.3 CVE-2025-30005 Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additional… Completepbx 5.2.36.1+ Fix from $1,9502025-03-31 MEDIUM 6.5 CVE-2025-2292 Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This … Completepbx 5.2.36.1+ Fix from $1,6002025-03-31 HIGH 8.7 CVE-2025-3021 Path Traversal vulnerability in e-solutions e-management. This vulnerability could allow an attacker to access confidential files outside the expecte… Mitigation only Fix from $1,9502025-03-31 HIGH 7.5 CVE-2025-2917 A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cm… Chestnutcms after 1.5.3 Fix from $1,9502025-03-28