Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Cs Cart Multivendor HIGH 7.2
CVE-2023-26691

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a …

No fix yet
Fix from $1,950 2024-09-25
Cs Cart Multivendor HIGH 8.8
CVE-2023-26687

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data paramete…

No fix yet
Fix from $1,950 2024-09-25
Wooevents CRITICAL 9.1
CVE-2024-8671

The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in…

Fix: 4.1.3+
Fix from $2,300 2024-09-24
Elementskit MEDIUM 6.5
CVE-2024-43996

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inc…

Fix: after 3.6.0
Fix from $1,600 2024-09-23
Mxview One MEDIUM 6.5
CVE-2024-6786

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on …

Fix: 1.4.1+
Fix from $1,600 2024-09-21
Enms MEDIUM 6.5
CVE-2024-46647

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.

Fix: 4.7.1+
Fix from $1,600 2024-09-20
Enms HIGH 7.5
CVE-2024-46648

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.

Fix: 4.7.1+
Fix from $1,950 2024-09-20
Enms HIGH 7.5
CVE-2024-46649

eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.

Fix: 4.7.1+
Fix from $1,950 2024-09-20
Enms MEDIUM 6.5
CVE-2024-46644

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

Fix: 4.7.1+
Fix from $1,600 2024-09-20
Enms HIGH 7.5
CVE-2024-46645

eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

No fix yet
Fix from $1,950 2024-09-20
Enms MEDIUM 6.5
CVE-2024-46646

eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.

Fix: 4.7.1+
Fix from $1,600 2024-09-20
Simple Forum\/discussion System HIGH 8.8
CVE-2024-9032

A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of…

No fix yet
Fix from $1,950 2024-09-20
Tiptel Ip 286 Firmware CRITICAL 9.8
CVE-2024-33109

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the p…

Fix: after 2.61.13.10
Fix from $2,300 2024-09-19
Endpoint Manager Cloud Services Appliance CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Mitigation only
Fix from $2,300 2024-09-19
Best House Rental Management System CRITICAL 9.8
CVE-2024-46375

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.

Mitigation only
Fix from $2,300 2024-09-18
Best House Rental Management System CRITICAL 9.8
CVE-2024-46376

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_cla…

Mitigation only
Fix from $2,300 2024-09-18
Camaleon Cms CRITICAL 9.9
CVE-2024-46986EPSS 37%

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upl…

Fix: 2.8.2+
Fix from $2,300 2024-09-18
Camaleon Cms HIGH 7.7
CVE-2024-46987EPSS 15%

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaControlle…

Fix: 2.8.2+
Fix from $1,950 2024-09-18
Unclassified HIGH 7.5
CVE-2024-45601

Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fixed in Mesop that could poten…

Patch available
Fix from $1,950 2024-09-18
Backstage MEDIUM 6.5
CVE-2024-45816

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access co…

Fix: 1.10.13+
Fix from $1,600 2024-09-17
Unclassified HIGH 7.2
CVE-2024-42501

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install un…

Mitigation only
Fix from $1,950 2024-09-17
Mautic HIGH 8.1
CVE-2021-27916

Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of…

Fix: 4.4.12 / 5.0.4+
Fix from $1,950 2024-09-17
File Handling HIGH 8.2
CVE-2024-47049

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and make…

Fix: 1.5.0 / 2.3.0+
Fix from $1,950 2024-09-17
macOS MEDIUM 5.5
CVE-2024-44190

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app …

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-44167

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ven…

Fix: 2.0 / 13.7+
Fix from $1,600 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-27869

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to record the screen …

Fix: 15.0 / 18.0+
Fix from $1,600 2024-09-17
Webiq HIGH 7.5
CVE-2024-8752EPSS 12%

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

No fix yet
Fix from $1,950 2024-09-16
Omflow MEDIUM 6.5
CVE-2024-8778

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges t…

Fix: 1.2.1.3+
Fix from $1,600 2024-09-16
Tpmecms HIGH 7.5
CVE-2024-8876

A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown func…

Fix: 1.3.3.2+
Fix from $1,950 2024-09-15
Wcms CRITICAL 9.1
CVE-2024-8875

A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /…

Fix: 0.3.2+
Fix from $2,300 2024-09-15