The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
154 vulnerabilities with CWE-35
CVE-2025-53880
HIGH
tftpsync - Path Traversal
CVE-2025-27222
HIGH
TRUfusion Enterprise <= 7.10.4.0 - Path Traversal
CVSS 8.6
CVE-2025-41723
CRITICAL
SOAP - Path Traversal
CVSS 9.8
CVE-2025-8051
MEDIUM
Opentext Flipper - Path Traversal
CVSS 6.5
CVE-2025-42937
CRITICAL
SAP Print Service - Path Traversal
CVSS 9.8
CVE-2025-43907
MEDIUM
Dell Data Domain Operating System < 7.10.1.70 - Path Traversal
CVSS 6.5
CVE-2025-20313
MEDIUM
Cisco IOS XE - Code Injection
CVSS 6.7
CVE-2025-43886
MEDIUM
Dell Powerprotect Data Manager < 19.21 - Path Traversal
CVSS 4.4
CVE-2025-48317
HIGH
Stefan Keller WooCommerce Payment Gateway <0.4.9 - Path Traversal
CVSS 7.5
CVE-2025-4956
MEDIUM
AA-Team Pro Bulk Watermark Plugin <2.0 - Path Traversal
CVSS 4.3
CVE-2025-48081
MEDIUM
Printeers Print & Ship <1.17.0 - Path Traversal
CVSS 5.3
CVE-2025-53561
MEDIUM
miniOrange <2.6.0 - Path Traversal
CVSS 6.5
CVE-2025-52712
MEDIUM
BoldGrid Post and Page Builder <1.27.8 - Path Traversal
CVSS 4.2
CVE-2025-8088
HIGH
KEV
Rarlab Winrar < 7.13 - Path Traversal
CVSS 8.8
CVE-2025-53417
CRITICAL
DIAView <4.2.0 - Info Disclosure
CVE-2025-20320
MEDIUM
Splunk <9.4.3, 9.3.5, 9.2.7, 9.1.10 - DoS
CVSS 6.3
CVE-2025-52805
HIGH
VaultDweller Leyka <3.31.9 - Path Traversal
CVSS 7.5
CVE-2025-52811
HIGH
Creanncy Davenport - Versatile Blog and Magazine WP Theme <1.3 - Pa...
CVSS 8.1
CVE-2025-52810
HIGH
TMRW-studio Katerio - Magazine <1.5.1 - Path Traversal
CVSS 8.1
CVE-2025-49451
HIGH
Aeroscroll Gallery <1.0.12 - Path Traversal
CVSS 7.5
CVE-2025-47176
HIGH
Microsoft 365 Apps - Path Traversal
CVSS 7.8
CVE-2025-30515
CRITICAL
CyberData 011209 Intercom - File Upload
CVSS 9.8
CVE-2025-49297
HIGH
Qodeinteractive Grill And Chow < 1.6.1 - Path Traversal
CVSS 8.1
CVE-2025-49296
HIGH
Qodeinteractive Grandprix < 1.6.1 - Path Traversal
CVSS 8.1
CVE-2025-49295
HIGH
Qodeinteractive Mediclinic < 2.2 - Path Traversal
CVSS 8.1
Details
Vulnerabilities
154