Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Chuanhuchatgpt CRITICAL 9.1
CVE-2024-6255EPSS 13%

A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, inclu…

No fix yet
Fix from $2,300 2024-07-31
Unclassified HIGH 7.5
CVE-2024-41695

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

No fix yet
Fix from $1,950 2024-07-30
macOS MEDIUM 5.5
CVE-2024-27887

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive d…

Fix: 14.4+
Fix from $1,600 2024-07-29
Ipados MEDIUM 5.5
CVE-2024-27871

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app may be able …

Fix: 14.6 / 17.6+
Fix from $1,600 2024-07-29
Internet Security HIGH 7.8
CVE-2024-7248

Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate priv…

Mitigation only
Fix from $1,950 2024-07-29
Tgstation Server CRITICAL 9.9
CVE-2024-41799

tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege cou…

Fix: 6.8.0+
Fix from $2,300 2024-07-29
Skysea Client View HIGH 7.5
CVE-2024-41726

Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable…

Fix: 19.300.09h+
Fix from $1,950 2024-07-29
Ultimate Classified Listings HIGH 7.5
CVE-2024-5882

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users …

Fix: 1.3+
Fix from $1,950 2024-07-29
Unclassified HIGH 7.5
CVE-2024-41628EPSS 6%

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allow…

Mitigation only
Fix from $1,950 2024-07-26
Unclassified MEDIUM 5.8
CVE-2024-42007

SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

Mitigation only
Fix from $1,600 2024-07-26
Icecoder MEDIUM 6.3
CVE-2024-41373

ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

No fix yet
Fix from $1,600 2024-07-26
Insurance Management System HIGH 7.5
CVE-2024-7080

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is a…

No fix yet
Fix from $1,950 2024-07-24
Devika CRITICAL 9.1
CVE-2024-40422EPSS 11%

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker c…

Patch available
Fix from $2,300 2024-07-24
Unclassified HIGH 8.1
CVE-2024-6885

The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient…

Mitigation only
Fix from $1,950 2024-07-23
Veristand HIGH 7.8
CVE-2024-6791

A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exp…

Fix: after 2024
Fix from $1,950 2024-07-22
Unclassified CRITICAL 9.8
CVE-2024-28698

Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the …

Patch available
Fix from $2,300 2024-07-22
Ip Guard HIGH 7.5
CVE-2024-40051

IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.

No fix yet
Fix from $1,950 2024-07-22
Unclassified HIGH 7.6
CVE-2020-24102

Directory Traversal vulnerability in Punkbuster pbsv.d64 2.351, allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2024-07-22
Bert Vits2 MEDIUM 6.5
CVE-2024-39688

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated with other folders and used to …

Fix: after 2.3
Fix from $1,600 2024-07-22
Librechat CRITICAL 9.8
CVE-2024-41704

LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

Fix: after 0.7.3
Fix from $2,300 2024-07-22
Wuhu MEDIUM 5.3
CVE-2024-6949

A vulnerability classified as problematic was found in Gargaj wuhu up to 3faad49bfcc3895e9ff76a591d05c8941273d120. Affected by this vulnerability is …

Fix: after 2024-02-10
Fix from $1,600 2024-07-21
Bazarr HIGH 8.2
CVE-2024-40348EPSS 8%

An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

Fix: after 1.4.3
Fix from $1,950 2024-07-20
Unclassified HIGH 7.3
CVE-2024-6281

A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does …

Patch available
Fix from $1,950 2024-07-20
Unclassified MEDIUM 6.5
CVE-2024-3934

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownload…

Mitigation only
Fix from $1,600 2024-07-20
Jumpserver CRITICAL 9.1
CVE-2024-40628

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, …

Fix: 3.10.12+
Fix from $2,300 2024-07-18
Jumpserver CRITICAL 9.8
CVE-2024-40629

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, …

Fix: 3.10.12+
Fix from $2,300 2024-07-18
Filter \& Grids CRITICAL 9.8
CVE-2024-6164

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an …

Fix: 2.8.33+
Fix from $2,300 2024-07-18
Access Rights Manager HIGH 8.8
CVE-2024-23475

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.3
CVE-2024-28992

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.3
CVE-2024-28993

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: 2024.3+
Fix from $1,950 2024-07-17