Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.1 CVE-2025-24888 The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. P… Patch available Fix from $1,9502025-02-13 MEDIUM 6.5 CVE-2024-47264 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup… Active Backup For Business Agent 2.7.1-3234 / 2.7.1-13234+ Fix from $1,6002025-02-13 CRITICAL 9.8 CVE-2024-10763 The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_a… Campress after 1.35 Fix from $2,3002025-02-13 HIGH 7.5 CVE-2024-51376 Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via the file/downloadFile.action… Mitigation only Fix from $1,9502025-02-12 MEDIUM 5.3 CVE-2024-6097 In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolu… Telerik Reporting 19.0.25.211+ Fix from $1,6002025-02-12 CRITICAL 9.8 CVE-2025-0332 In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressi… Telerik Ui For Winforms 2025.1.211+ Fix from $2,3002025-02-12 HIGH 8.8 CVE-2024-11343 In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system a… Telerik Document Processing Libraries 2025.1.205+ Fix from $1,9502025-02-12 MEDIUM 5.1 CVE-2024-57777 Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information Lanproxy No fix yet Fix from $1,6002025-02-11 HIGH 7.5 CVE-2025-24406 Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a R… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502025-02-11 MEDIUM 6.0 CVE-2024-36508 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 throu… Fortimanager 7.2.6 / 7.4.3+ Fix from $1,6002025-02-11 MEDIUM 5.3 CVE-2024-11771 Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality. Cloud Services Appliance 5.0.5+ Fix from $1,6002025-02-11 HIGH 8.6 CVE-2025-25243 SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to downl… Mitigation only Fix from $1,9502025-02-11 HIGH 7.2 CVE-2024-13059EPSS 21% A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the… Anythingllm 1.3.1+ Fix from $1,9502025-02-10 MEDIUM 6.5 CVE-2025-1106 A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library li… Cmseasy No fix yet Fix from $1,6002025-02-07 MEDIUM 6.3 CVE-2024-57248 Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Esca… Filevista No fix yet Fix from $1,6002025-02-07 MEDIUM 6.5 CVE-2024-55213 Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing functio… File Explorer No fix yet Fix from $1,6002025-02-07 MEDIUM 6.5 CVE-2024-55214 Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download funct… File Explorer No fix yet Fix from $1,6002025-02-07 HIGH 7.5 CVE-2024-52883 An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be… One Voice Operations Center 8.4.582+ Fix from $1,9502025-02-07 HIGH 7.5 CVE-2025-25155 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in efreja Music Sheet Viewer music-sheet-viewer allows P… Mitigation only Fix from $1,9502025-02-07 CRITICAL 9.8 CVE-2025-25163 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer images-optimize… Plugin A\/b Image Optimizer after 3.3 Fix from $2,3002025-02-07 MEDIUM 5.3 CVE-2024-53586 An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecti… Mitigation only Fix from $1,6002025-02-06 HIGH 8.1 CVE-2024-54909 A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, wher… Mitigation only Fix from $1,9502025-02-06 CRITICAL 9.1 CVE-2025-24786 WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no p… Whodb 0.45.0+ Fix from $2,3002025-02-06 MEDIUM 6.5 CVE-2025-0859 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and i… Post And Page Builder 1.27.7+ Fix from $1,6002025-02-06 MEDIUM 6.5 CVE-2025-0799 IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file … App Connect Enterprise after 13.0.2.1 Fix from $1,6002025-02-06 HIGH 7.5 CVE-2025-24963 Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file sy… Vitest 2.1.9 / 3.0.4+ Fix from $1,9502025-02-04 MEDIUM 5.4 CVE-2024-48019 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in … Doris 2.1.8 / 3.0.3+ Fix from $1,6002025-02-04 HIGH 7.5 CVE-2025-22205 Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.… Admiror Gallery after 4.5.0 Fix from $1,9502025-02-04 HIGH 8.7 CVE-2025-24960 Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This … Patch available Fix from $1,9502025-02-03 MEDIUM 6.0 CVE-2025-24961 org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expos… Patch available Fix from $1,6002025-02-03