Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2025-27142 LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over their local network without need… Localsend 1.17.0+ Fix from $1,9502025-02-25 HIGH 8.8 CVE-2025-26935 Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal… Wp Job Portal after 2.2.8 Fix from $1,9502025-02-25 HIGH 7.5 CVE-2025-26905 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik allows PHP Local File Inclusi… Mitigation only Fix from $1,9502025-02-25 HIGH 8.6 CVE-2025-26752 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-s… Mitigation only Fix from $1,9502025-02-25 HIGH 7.5 CVE-2025-26753 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-s… Mitigation only Fix from $1,9502025-02-25 MEDIUM 6.5 CVE-2025-20051 Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicat… Mattermost Server 9.11.8 / 10.2.3+ Fix from $1,6002025-02-24 HIGH 7.5 CVE-2025-25279EPSS 24% Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boar… Mattermost Server 9.11.8 / 10.2.3+ Fix from $1,9502025-02-24 CRITICAL 9.1 CVE-2025-1599 A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unk… Best Church Management Software No fix yet Fix from $2,3002025-02-24 CRITICAL 9.1 CVE-2025-1588 A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of th… Online Nurse Hiring System Mitigation only Fix from $2,3002025-02-23 HIGH 7.5 CVE-2025-27098 GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, su… Graphql Mesh Cli 0.3.19 / 0.82.22+ Fix from $1,9502025-02-20 MEDIUM 6.5 CVE-2024-55457 MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulat… Mitigation only Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2024-49780 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges … Openpages With Watson 8.3.0.3 / 9.0.0.5+ Fix from $1,6002025-02-20 HIGH 7.5 CVE-2025-27092 GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was … Ghosts 8.2.7.90+ Fix from $1,9502025-02-19 HIGH 8.5 CVE-2025-24965 crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into e… Patch available Fix from $1,9502025-02-19 HIGH 7.5 CVE-2025-26616 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the … Wegia 3.2.14+ Fix from $1,9502025-02-18 HIGH 7.5 CVE-2025-26615 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the … Wegia 3.2.14+ Fix from $1,9502025-02-18 HIGH 8.6 CVE-2025-22663 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-web… Mitigation only Fix from $1,9502025-02-18 HIGH 8.7 CVE-2025-25284 The ZOO-Project is an open source processing platform, released under MIT/X11 Licence. A vulnerability in ZOO-Project's WPS (Web Processing Service) … Patch available Fix from $1,9502025-02-18 MEDIUM 5.7 CVE-2025-1035EPSS 10% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating W… Mitigation only Fix from $1,6002025-02-18 CRITICAL 9.8 CVE-2024-13725 The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service… Keap Official Opt In Forms after 2.0.1 Fix from $2,3002025-02-18 MEDIUM 5.3 CVE-2024-13538 The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.… Dropshipping Connector For Woocommerce after 1.9.19 Fix from $1,6002025-02-18 MEDIUM 5.3 CVE-2024-13535 The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.2. This is due the … Actionwear Products Sync 2.3.3+ Fix from $1,6002025-02-18 MEDIUM 5.3 CVE-2025-25223 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. … Luxcal Web Calendar 5.3.3l / 5.3.3m+ Fix from $1,6002025-02-18 HIGH 8.1 CVE-2025-1336 A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. Affected by this vulnerability is the function deleteimg_action in t… Cmseasy No fix yet Fix from $1,9502025-02-16 HIGH 8.1 CVE-2025-1335 A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. Affected is the function deleteimg_action in the library lib/admi… Cmseasy No fix yet Fix from $1,9502025-02-16 MEDIUM 6.5 CVE-2025-0822 Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it p… Bit Assist 1.5.3+ Fix from $1,6002025-02-15 HIGH 7.5 CVE-2025-25997 Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component. Feminer Wms No fix yet Fix from $1,9502025-02-14 HIGH 8.7 CVE-2025-25295 Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized fi… Patch available Fix from $1,9502025-02-14 MEDIUM 6.5 CVE-2024-56477 IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a … Power Hardware Management Console Mitigation only Fix from $1,6002025-02-14 CRITICAL 9.1 CVE-2025-1127 The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the fil… No fix yet Fix from $2,3002025-02-13