Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Collaboration HIGH 7.5
CVE-2024-33535

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web ap…

Fix: 10.0.8+
Fix from $1,950 2024-08-12
Raidenmaild HIGH 7.5
CVE-2024-7693

Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attack…

Fix: 5.0.2+
Fix from $1,950 2024-08-12
Magicinfo 9 Server CRITICAL 9.8
CVE-2024-7399 KEVEPSS 92%

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wr…

Fix: 21.1050.0+
Fix from $2,300 2024-08-12
FreeBSD MEDIUM 5.3
CVE-2024-6759

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This all…

Fix: 13.0 / 13.3+
Fix from $1,600 2024-08-12
Openhab CRITICAL 9.8
CVE-2024-42469

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometV…

Fix: 4.2.1+
Fix from $2,300 2024-08-12
Openhab HIGH 7.5
CVE-2024-42468

openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions p…

Fix: 4.2.1+
Fix from $1,950 2024-08-12
Var1200 H Firmware HIGH 7.5
CVE-2024-41936

A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior…

Fix: after 3.3.23.6.9
Fix from $1,950 2024-08-12
Iq Gateway Firmware CRITICAL 9.1
CVE-2024-21876

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly know…

Fix: 8.2.4225+
Fix from $2,300 2024-08-12
Iq Gateway Firmware MEDIUM 6.5
CVE-2024-21877

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly …

Fix: 8.2.4225+
Fix from $1,600 2024-08-12
Mlnx Os HIGH 8.8
CVE-2024-0113

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a …

Fix: 3.10.4500 / 3.10.4504+
Fix from $1,950 2024-08-12
Open Webui HIGH 8.8
CVE-2024-6707

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

No fix yet
Fix from $1,950 2024-08-07
Verify HIGH 7.8
CVE-2024-7061

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.…

Fix: 5.0.2+
Fix from $1,950 2024-08-07
Docs\@work MEDIUM 5.5
CVE-2024-37403

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, r…

Fix: 2.26.0+
Fix from $1,600 2024-08-07
Unified Secops Platform MEDIUM 6.5
CVE-2024-7564

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sens…

Mitigation only
Fix from $1,600 2024-08-06
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39226EPSS 21%

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Page Builder HIGH 8.8
CVE-2024-5709

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_nam…

Fix: 7.8+
Fix from $1,950 2024-08-06
Calibre HIGH 7.5
CVE-2024-6781EPSS 62%

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

Fix: after 7.14.0
Fix from $1,950 2024-08-06
Nuxt HIGH 8.8
CVE-2024-23657

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on t…

Fix: 1.3.9+
Fix from $1,950 2024-08-05
Eladmin CRITICAL 9.8
CVE-2024-7458

A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/…

Fix: after 2.7
Fix from $2,300 2024-08-04
Andserver HIGH 7.5
CVE-2024-41310

AndServer 2.1.12 is vulnerable to Directory Traversal.

Fix: after 2.1.12
Fix from $1,950 2024-08-02
Easyflow .net MEDIUM 6.5
CVE-2024-7323

Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote att…

Fix: 6.6.17+
Fix from $1,600 2024-08-02
Omnivise T3000 Application Server MEDIUM 6.5
CVE-2024-38878EPSS 11%

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 …

Mitigation only
Fix from $1,600 2024-08-02
Listingpro HIGH 7.2
CVE-2024-39621

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP …

Fix: 2.9.5+
Fix from $1,950 2024-08-01
Listingpro HIGH 8.8
CVE-2024-39624

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local F…

Fix: 2.9.5+
Fix from $1,950 2024-08-01
Unclassified MEDIUM 6.5
CVE-2024-38772

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce a…

Mitigation only
Fix from $1,600 2024-08-01
Listingpro CRITICAL 9.8
CVE-2024-39619

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP …

Fix: 2.9.5+
Fix from $2,300 2024-08-01
Unclassified HIGH 7.1
CVE-2024-38746

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories)…

Mitigation only
Fix from $1,950 2024-08-01
The Pack Elementor Addons HIGH 8.8
CVE-2024-38768

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local F…

Fix: 2.0.8.7+
Fix from $1,950 2024-08-01
Unclassified HIGH 8.8
CVE-2024-7340

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse …

Patch available
Fix from $1,950 2024-07-31
Inventory Collector HIGH 7.8
CVE-2024-37129

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially …

Fix: 12.3.0.6+
Fix from $1,950 2024-07-31