Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.1 CVE-2024-7776 A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite… Onnx after 1.16.1 Fix from $2,3002025-03-20 HIGH 7.2 CVE-2024-7034 In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames.… Open Webui No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-6851 In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleti… Aim No fix yet Fix from $1,9502025-03-20 CRITICAL 9.1 CVE-2024-5752 A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a… Patch available Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-12866 A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files… Qanything No fix yet Fix from $1,9502025-03-20 MEDIUM 5.3 CVE-2024-12217 A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_… Mitigation only Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12065 A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the s… Llava No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-11037 A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection… Gpt Academic No fix yet Fix from $1,6002025-03-20 CRITICAL 9.8 CVE-2024-10902 In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This … Db Gpt No fix yet Fix from $2,3002025-03-20 MEDIUM 6.5 CVE-2024-10948 A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files … Gpt Academic No fix yet Fix from $1,6002025-03-20 HIGH 8.2 CVE-2024-10830 A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability all… Db Gpt No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-10707 gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, wh… Chuanhuchatgpt No fix yet Fix from $1,6002025-03-20 HIGH 7.2 CVE-2024-10513 A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to … Anythingllm 1.2.2+ Fix from $1,9502025-03-20 CRITICAL 9.1 CVE-2024-10361 An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulner… Librechat Patch available Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2025-2505 The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. Thi… Mitigation only Fix from $2,3002025-03-20 HIGH 8.8 CVE-2025-1770 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… Eventin 4.0.25+ Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2025-27782 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to wri… Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 CRITICAL 9.8 CVE-2025-27783 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing… Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 HIGH 7.5 CVE-2025-27785 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This … Applio after 3.2.8-bugfix Fix from $1,9502025-03-19 CRITICAL 9.1 CVE-2025-27786 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py t… Applio after 3.2.8-bugfix Fix from $2,3002025-03-19 HIGH 7.5 CVE-2025-27787 Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py … Applio after 3.2.8-bugfix Fix from $1,9502025-03-19 MEDIUM 6.5 CVE-2024-57170 SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attack… Soplanning No fix yet Fix from $1,6002025-03-18 HIGH 8.8 CVE-2025-2449EPSS 32% NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create a… Flexlogger Mitigation only Fix from $1,9502025-03-18 HIGH 7.5 CVE-2025-2493 Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘… Softdial Contact Center Mitigation only Fix from $1,9502025-03-18 MEDIUM 6.6 CVE-2025-0694 Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access. Mitigation only Fix from $1,6002025-03-18 MEDIUM 5.3 CVE-2024-8510 N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. Thi… N Central 2024.6+ Fix from $1,6002025-03-17 HIGH 7.5 CVE-2025-25684 A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the dev… Mitigation only Fix from $1,9502025-03-17 HIGH 7.5 CVE-2025-25685 An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding… Mitigation only Fix from $1,9502025-03-17 HIGH 7.3 CVE-2025-29787 `zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the… Patch available Fix from $1,9502025-03-17 CRITICAL 9.8 CVE-2025-2363 A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/… Vblog Mitigation only Fix from $2,3002025-03-17