Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.6 CVE-2024-54291 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass pluginpass-pro-plugintheme-licensin… Mitigation only Fix from $1,9502025-03-28 MEDIUM 6.5 CVE-2025-27716 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB storage fil… Mitigation only Fix from $1,6002025-03-28 HIGH 8.8 CVE-2025-27718 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharin… Mitigation only Fix from $1,9502025-03-28 HIGH 8.1 CVE-2025-27932 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-shar… Mitigation only Fix from $1,9502025-03-28 HIGH 8.8 CVE-2025-2328 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path… Drag And Drop Multiple File Upload Contact Form 7 1.3.8.8+ Fix from $1,9502025-03-28 CRITICAL 9.8 CVE-2025-2294EPSS 78% The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_… Mitigation only Fix from $2,3002025-03-28 HIGH 7.5 CVE-2024-12905 An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal").… Patch available Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30895 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP L… Mitigation only Fix from $1,9502025-03-27 MEDIUM 6.5 CVE-2025-1310 The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_g… Mitigation only Fix from $1,6002025-03-26 CRITICAL 9.8 CVE-2025-27837 An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 charac… Ghostscript 10.05.0+ Fix from $2,3002025-03-25 HIGH 7.5 CVE-2025-29789 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Di… Openemr 7.0.3+ Fix from $1,9502025-03-25 HIGH 7.5 CVE-2025-25371 NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system. Core Flight System No fix yet Fix from $1,9502025-03-25 HIGH 7.5 CVE-2025-30567 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affec… Mitigation only Fix from $1,9502025-03-25 HIGH 8.2 CVE-2025-27147 The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWa… Patch available Fix from $1,9502025-03-25 MEDIUM 5.4 CVE-2025-2744 A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin… Ruoyi Vue Pro No fix yet Fix from $1,6002025-03-25 HIGH 8.1 CVE-2025-2742 A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api… Ruoyi Vue Pro No fix yet Fix from $1,9502025-03-25 HIGH 8.1 CVE-2025-2743 A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing… Ruoyi Vue Pro No fix yet Fix from $1,9502025-03-25 CRITICAL 9.1 CVE-2025-2708 A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-ap… Ruoyi Vue Pro No fix yet Fix from $2,3002025-03-24 HIGH 7.2 CVE-2025-2749 KEV An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative … Xperience after 13.0.178 Fix from $1,9502025-03-24 CRITICAL 9.1 CVE-2025-2707 A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functi… Ruoyi Vue Pro No fix yet Fix from $2,3002025-03-24 MEDIUM 6.5 CVE-2025-30343 A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The int… Openslides 4.2.5+ Fix from $1,6002025-03-21 HIGH 7.1 CVE-2024-9597 A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory o… Mitigation only Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-9362 An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retri… Mitigation only Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-9415 A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an at… Superagi No fix yet Fix from $1,9502025-03-20 CRITICAL 9.1 CVE-2024-8769 A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path… Aim 3.24.0+ Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2024-8898 A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab… Lollms Web Ui Patch available Fix from $2,3002025-03-20 CRITICAL 9.1 CVE-2024-8581 A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the syst… Lollms Web Ui Patch available Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-8438 A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` pa… Agentscope No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-8524 A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON … Agentscope No fix yet Fix from $1,9502025-03-20 HIGH 8.1 CVE-2024-8060 OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The … Mitigation only Fix from $1,9502025-03-20