Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Access Rights Manager HIGH 8.0
CVE-2024-23472EPSS 19%

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitr…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23474

The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23466

SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23467

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.3
CVE-2024-23468

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Network Edgiot Gw1500 Firmware MEDIUM 6.5
CVE-2024-40617

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privileg…

Mitigation only
Fix from $1,600 2024-07-17
Seacms MEDIUM 6.5
CVE-2024-39036

SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

No fix yet
Fix from $1,600 2024-07-16
Unclassified CRITICAL 9.8
CVE-2024-40524

Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.

Mitigation only
Fix from $2,300 2024-07-15
Meeting Software Development Kit MEDIUM 6.8
CVE-2024-39826

Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via n…

Fix: 5.17.13 / 6.0.0+
Fix from $1,600 2024-07-15
Easyspider HIGH 8.8
CVE-2024-6746

A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functional…

No fix yet
Fix from $1,950 2024-07-15
Datacap MEDIUM 5.3
CVE-2024-39741

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the system. An attacker could se…

Mitigation only
Fix from $1,600 2024-07-15
Storage Concentrator MEDIUM 6.5
CVE-2024-31947

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with th…

Fix: 8.0.4.26+
Fix from $1,600 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40550

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Unclassified MEDIUM 6.5
CVE-2024-38716

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Calendar for Google allows PHP Lo…

Mitigation only
Fix from $1,600 2024-07-12
Unclassified HIGH 7.1
CVE-2024-38717

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows PHP Local File Inclusion.Thi…

Mitigation only
Fix from $1,950 2024-07-12
Solara HIGH 7.5
CVE-2024-39903

Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgett…

Fix: 1.35.1+
Fix from $1,950 2024-07-12
Unclassified MEDIUM 6.5
CVE-2024-38715

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows PHP Local File Inclusion.This …

Mitigation only
Fix from $1,600 2024-07-12
Unclassified MEDIUM 5.3
CVE-2024-38709

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File…

Mitigation only
Fix from $1,600 2024-07-12
Unclassified MEDIUM 6.5
CVE-2024-38704

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress Team Manager allows PHP Local…

Mitigation only
Fix from $1,600 2024-07-12
Unclassified HIGH 8.6
CVE-2024-37928

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This iss…

Mitigation only
Fix from $1,950 2024-07-12
Unclassified HIGH 8.6
CVE-2024-37932

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce OpenPos allows File Manipulation.…

Mitigation only
Fix from $1,950 2024-07-12
Foxrtu Station HIGH 7.8
CVE-2024-2602

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code executio…

Fix: 9.3.0+
Fix from $1,950 2024-07-11
Pingfederate MEDIUM 5.3
CVE-2024-22377

The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.

Fix: after 11.3.4
Fix from $1,600 2024-07-09
Phpvibe CRITICAL 9.8
CVE-2024-39171

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specifi…

Fix: after 11.0.46
Fix from $2,300 2024-07-09
Wpcafe HIGH 8.8
CVE-2024-37513

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue a…

Fix: 2.2.28+
Fix from $1,950 2024-07-09
Unclassified HIGH 7.7
CVE-2024-37497

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetThemeCore jet-theme-core.This issue aff…

Mitigation only
Fix from $1,950 2024-07-09
Online Booking \& Scheduling Calendar MEDIUM 6.5
CVE-2024-37499

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & Scheduling Calendar for WordPr…

Fix: 4.4.3+
Fix from $1,600 2024-07-09
Unclassified HIGH 8.5
CVE-2024-37501

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allo…

Mitigation only
Fix from $1,950 2024-07-09
Ultimate Bootstrap Elements For Elementor HIGH 8.8
CVE-2024-37462

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor all…

Fix: 1.4.3+
Fix from $1,950 2024-07-09
Website Builder MEDIUM 5.4
CVE-2024-37437

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.T…

Fix: 3.22.2+
Fix from $1,600 2024-07-09