Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-42225 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 HIGH 7.5 CVE-2023-42226 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 HIGH 7.5 CVE-2023-42227 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 MEDIUM 6.5 CVE-2023-42229 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticat… Helpdeskadvanced after 11.0.33 Fix from $1,6002025-01-13 MEDIUM 5.3 CVE-2025-0401 A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/ithei… Reggie Mitigation only Fix from $1,6002025-01-13 CRITICAL 9.1 CVE-2025-22152 Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple component… Mitigation only Fix from $2,3002025-01-10 CRITICAL 9.8 CVE-2024-11642 The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin … Post Grid Master after 3.4.12 Fix from $2,3002025-01-09 HIGH 8.8 CVE-2025-22130 Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and… Soft Serve 0.8.2+ Fix from $1,9502025-01-08 HIGH 7.5 CVE-2024-9939 The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.… Wordpress File Upload 4.24.14+ Fix from $1,9502025-01-08 MEDIUM 5.3 CVE-2024-10585 The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter… Infinitewp Client 1.13.1+ Fix from $1,6002025-01-08 CRITICAL 9.1 CVE-2023-52953 Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiali… Emui Mitigation only Fix from $2,3002025-01-08 CRITICAL 9.1 CVE-2025-21622 ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avata… Clipbucket 5.5.1-237+ Fix from $2,3002025-01-07 HIGH 7.5 CVE-2025-21623 ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the templat… Clipbucket 5.5.1-238+ Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-56286 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder… Mitigation only Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-12152 The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.5 via the 'mipl_wc_syn… Mitigation only Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-12849EPSS 47% The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_aj… Mitigation only Fix from $1,9502025-01-07 MEDIUM 6.5 CVE-2024-41765 IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker … Engineering Lifecycle Optimization Publishing Mitigation only Fix from $1,6002025-01-04 MEDIUM 5.3 CVE-2024-56514 Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to… Patch available Fix from $1,6002025-01-03 CRITICAL 9.3 CVE-2024-56198 path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the filters can be bypassed using … Patch available Fix from $2,3002024-12-31 MEDIUM 6.5 CVE-2024-12105EPSS 42% In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclo… Whatsup Gold 24.0.2+ Fix from $1,6002024-12-31 HIGH 8.8 CVE-2024-56213 Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <… Eventin 4.0.9+ Fix from $1,9502024-12-31 HIGH 8.8 CVE-2024-11944 iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attacke… Truenas Firmware Mitigation only Fix from $1,9502024-12-30 HIGH 7.5 CVE-2024-54453 An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnera… Mitigation only Fix from $1,9502024-12-27 HIGH 8.6 CVE-2024-56509 changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validat… Patch available Fix from $1,9502024-12-27 MEDIUM 5.1 CVE-2024-41887 Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can create an NVR log file in a … No fix yet Fix from $1,6002024-12-24 HIGH 8.1 CVE-2024-53961EPSS 14% ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vu… Coldfusion Mitigation only Fix from $1,9502024-12-23 CRITICAL 9.8 CVE-2024-54148 Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access… Gogs 0.13.1+ Fix from $2,3002024-12-23 HIGH 8.8 CVE-2024-55947EPSS 75% Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the… Gogs 0.13.1+ Fix from $1,9502024-12-23 MEDIUM 6.8 CVE-2024-56331 Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local f… Patch available Fix from $1,6002024-12-20 HIGH 7.5 CVE-2024-44195 A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files. macOS Mitigation only Fix from $1,9502024-12-20