Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.5
CVE-2024-43271

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Products Widgets For Elementor allo…

Mitigation only
Fix from $1,950 2024-08-19
Unclassified MEDIUM 5.3
CVE-2024-43281

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elemen…

Mitigation only
Fix from $1,600 2024-08-19
Bit Form CRITICAL 9.1
CVE-2024-43248

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This i…

Fix: after 2.6.4
Fix from $2,300 2024-08-19
Unclassified HIGH 8.5
CVE-2024-43221

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilder allows PHP Local File Inclu…

Mitigation only
Fix from $1,950 2024-08-19
Unclassified HIGH 8.5
CVE-2024-43232

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and Histo…

Mitigation only
Fix from $1,950 2024-08-19
Mobile Security Framework CRITICAL 9.8
CVE-2024-43399

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy…

Fix: 4.0.7+
Fix from $2,300 2024-08-19
Backwpup MEDIUM 6.8
CVE-2023-5505

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. Th…

Fix: 4.0.2+
Fix from $1,600 2024-08-17
Unclassified HIGH 8.2
CVE-2024-43395

CraftOS-PC 2 is a rewrite of the desktop port of CraftOS from the popular Minecraft mod ComputerCraft using C++ and a modified version of PUC Lua, as…

Patch available
Fix from $1,950 2024-08-16
Jetelements HIGH 8.8
CVE-2024-7145

The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' param…

Fix: after 2.6.20
Fix from $1,950 2024-08-16
Unclassified HIGH 8.8
CVE-2024-7146

The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.3 via the 'switcher_pr…

Mitigation only
Fix from $1,950 2024-08-16
Wps Office HIGH 7.8
CVE-2024-7262 KEV

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows al…

Fix: 12.2.0.16412+
Fix from $1,950 2024-08-15
Wps Office HIGH 7.8
CVE-2024-7263

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows al…

Fix: 12.2.0.17153+
Fix from $1,950 2024-08-15
Webcrack HIGH 7.8
CVE-2024-43373

webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifical…

Fix: 2.14.1+
Fix from $1,950 2024-08-15
Super Easy Enterprise Management System MEDIUM 5.5
CVE-2024-42680

An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a singl…

Fix: after 1.0.0
Fix from $1,600 2024-08-15
Comfortkey HIGH 7.5
CVE-2024-27120

A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacke…

Fix: 24.1.2+
Fix from $1,950 2024-08-14
Commerce MEDIUM 6.8
CVE-2024-39406

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direc…

Fix: after 2.4.3
Fix from $1,600 2024-08-14
Commerce HIGH 7.7
CVE-2024-39399

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direc…

Fix: after 2.4.3
Fix from $1,950 2024-08-14
Avalanche CRITICAL 9.1
CVE-2024-38652EPSS 8%

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a…

Mitigation only
Fix from $2,300 2024-08-14
Ltcms MEDIUM 5.3
CVE-2024-7741

A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/d…

No fix yet
Fix from $1,600 2024-08-13
Markdown Pdf HIGH 7.8
CVE-2024-7738

A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,950 2024-08-13
Unclassified HIGH 8.5
CVE-2024-6618

In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of …

Mitigation only
Fix from $1,950 2024-08-13
Unclassified MEDIUM 6.5
CVE-2024-43165

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allows PHP Local File Inclusion.Th…

Mitigation only
Fix from $1,600 2024-08-13
Event Manager And Tickets Selling For Woocommerce HIGH 8.8
CVE-2024-43138

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows …

Fix: 4.2.2+
Fix from $1,950 2024-08-13
Ultimate Bootstrap Elements For Elementor HIGH 8.8
CVE-2024-43140

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor all…

Fix: 1.4.5+
Fix from $1,950 2024-08-13
Wpcafe HIGH 8.8
CVE-2024-43135

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.Th…

Fix: 2.2.29+
Fix from $1,950 2024-08-13
Betterdocs HIGH 8.8
CVE-2024-43129

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusio…

Fix: 3.5.9+
Fix from $1,950 2024-08-13
Woocommerce Pdf Vouchers CRITICAL 9.3
CVE-2024-39651

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulati…

Fix: 4.9.5+
Fix from $2,300 2024-08-13
Streamlit MEDIUM 6.5
CVE-2024-42474

Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the…

Fix: 1.37.0+
Fix from $1,600 2024-08-12
Filament Excel HIGH 7.5
CVE-2024-42485

Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file wit…

Fix: 1.1.14 / 2.3.3+
Fix from $1,950 2024-08-12
Directory Services CRITICAL 9.8
CVE-2023-7249

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Trav…

Fix: 24.1+
Fix from $2,300 2024-08-12