Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Jfinalcms CRITICAL 9.8
CVE-2024-8782

A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/e…

Fix: after 1.0
Fix from $2,300 2024-09-13
Unclassified HIGH 7.5
CVE-2024-38816EPSS 15%

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An atta…

No fix yet
Fix from $1,950 2024-09-13
Pavilion8 CRITICAL 9.8
CVE-2024-7961

A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to th…

Fix: 6.0+
Fix from $2,300 2024-09-12
Jfinalcms MEDIUM 6.5
CVE-2024-8706

A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/tem…

Fix: 20240903+
Fix from $1,600 2024-09-12
Voc Tester HIGH 7.5
CVE-2024-7609

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal. Thi…

Fix: 12.34.8+
Fix from $1,950 2024-09-11
Nix HIGH 8.8
CVE-2024-45593

Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR th…

Fix: 2.24.6+
Fix from $1,950 2024-09-10
Forticlient Endpoint Management Server MEDIUM 6.0
CVE-2024-21753

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 throu…

Fix: after 7.2.4
Fix from $1,600 2024-09-10
Phpok HIGH 7.5
CVE-2024-44867

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

No fix yet
Fix from $1,950 2024-09-10
Unclassified HIGH 7.5
CVE-2024-37728

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obt…

No fix yet
Fix from $1,950 2024-09-10
Seacms HIGH 7.5
CVE-2024-44720

SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

No fix yet
Fix from $1,950 2024-09-09
Orca Hcm MEDIUM 6.5
CVE-2024-8585

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with reg…

Fix: 11.0+
Fix from $1,600 2024-09-09
Veeam Backup \& Replication HIGH 7.8
CVE-2024-40712

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation …

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Unclassified HIGH 7.7
CVE-2023-30584

A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handl…

Mitigation only
Fix from $1,950 2024-09-07
Qts MEDIUM 6.5
CVE-2024-21904

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users …

Mitigation only
Fix from $1,600 2024-09-06
Qts MEDIUM 6.5
CVE-2023-51366

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users …

Mitigation only
Fix from $1,600 2024-09-06
Datadiodex HIGH 7.5
CVE-2024-6445

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal…

Fix: 3.1.7+
Fix from $1,950 2024-09-06
Stripe Cli HIGH 7.1
CVE-2024-45401

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to vers…

Fix: 1.21.3+
Fix from $1,950 2024-09-05
C Mor Video Surveillance HIGH 8.8
CVE-2024-45175

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive…

No fix yet
Fix from $1,950 2024-09-05
C Mor Video Surveillance HIGH 7.1
CVE-2024-45178

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary f…

No fix yet
Fix from $1,950 2024-09-05
Webmethods Integration MEDIUM 6.5
CVE-2024-45074

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted …

Mitigation only
Fix from $1,600 2024-09-04
Abcd HIGH 7.5
CVE-2024-8410

A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/…

Mitigation only
Fix from $1,950 2024-09-04
Abcd HIGH 7.5
CVE-2024-8409

A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_imag…

Mitigation only
Fix from $1,950 2024-09-04
Wp Extended MEDIUM 6.5
CVE-2024-8104

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.…

Fix: 3.0.9+
Fix from $1,600 2024-09-04
Notes HIGH 7.8
CVE-2024-34656

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Fix: 4.4.21.62+
Fix from $1,950 2024-09-04
Wp Job Portal CRITICAL 9.8
CVE-2024-7950

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitr…

Fix: 2.1.7+
Fix from $2,300 2024-09-04
Emui CRITICAL 9.1
CVE-2024-45443

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiali…

Mitigation only
Fix from $2,300 2024-09-04
Hoverfly HIGH 7.5
CVE-2024-45388EPSS 56%

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler…

Fix: 1.10.3+
Fix from $1,950 2024-09-02
Overleaf MEDIUM 5.3
CVE-2024-45312

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) co…

Fix: 4.2.7 / 5.0.7+
Fix from $1,600 2024-09-02
Actions\/artifact HIGH 7.5
CVE-2024-42471

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable t…

Fix: 2.1.7+
Fix from $1,950 2024-09-02
Droip HIGH 7.5
CVE-2024-43955

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows File Manipulation.This issue aff…

Fix: after 1.1.1
Fix from $1,950 2024-08-29