Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Awsm Team HIGH 8.8
CVE-2024-37454

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AWSM Innovations AWSM Team allows Path Traversal.This…

Fix: 1.3.2+
Fix from $1,950 2024-07-09
Cowidgets HIGH 8.8
CVE-2024-37419

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Codeless Cowidgets – Elementor Addons allows Path Tra…

Fix: 1.2.0+
Fix from $1,950 2024-07-09
Tutor Lms HIGH 7.2
CVE-2024-37266

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue af…

Fix: 2.7.2+
Fix from $1,950 2024-07-09
Striking HIGH 8.8
CVE-2024-37268

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kaptinlin Striking allows Path Traversal.This issue a…

Fix: 2.3.5+
Fix from $1,950 2024-07-09
Sp Project \& Document Manager MEDIUM 6.5
CVE-2024-37224

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue …

Fix: after 4.71
Fix from $1,600 2024-07-09
Unclassified HIGH 8.8
CVE-2024-5456

The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' para…

Mitigation only
Fix from $1,950 2024-07-09
Elementor Addons MEDIUM 6.5
CVE-2024-37547

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue aff…

Fix: 8.4.1+
Fix from $1,600 2024-07-06
Unclassified MEDIUM 5.4
CVE-2024-39178

MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump/tcpdump.php?menu_uuid.

Mitigation only
Fix from $1,600 2024-07-05
Supos HIGH 7.5
CVE-2024-39937

supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.

Mitigation only
Fix from $1,950 2024-07-04
Addons For Elementor HIGH 8.8
CVE-2024-2385

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.4 via several of …

Fix: after 8.3.7
Fix from $1,950 2024-07-04
Ghostscript MEDIUM 5.3
CVE-2024-33869

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) bec…

Fix: 10.03.1+
Fix from $1,600 2024-07-03
Ghostscript MEDIUM 6.3
CVE-2024-33870

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the …

Fix: 10.03.1+
Fix from $1,600 2024-07-03
Unclassified MEDIUM 6.2
CVE-2024-5821

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests t…

No fix yet
Fix from $1,600 2024-07-03
Privileged Access Service MEDIUM 6.5
CVE-2024-5865

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary fi…

Fix: after 22.3
Fix from $1,600 2024-07-02
Element Kit For Elementor HIGH 8.8
CVE-2024-5349

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via …

Fix: 1.3.9+
Fix from $1,950 2024-07-02
Splunk HIGH 7.5
CVE-2024-36991EPSS 13%

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoi…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Geoserver HIGH 7.5
CVE-2024-24749

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed…

Fix: 2.23.5 / 2.24.3+
Fix from $1,950 2024-07-01
Bc500 Firmware MEDIUM 5.3
CVE-2023-47803

A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functional…

Fix: 1.0.7-0298+
Fix from $1,600 2024-06-28
Unclassified CRITICAL 9.4
CVE-2024-36059

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files …

Mitigation only
Fix from $2,300 2024-06-27
Unclassified CRITICAL 9.8
CVE-2024-6127EPSS 10%

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker ca…

Mitigation only
Fix from $2,300 2024-06-27
Unclassified HIGH 8.6
CVE-2024-6085

A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to …

Mitigation only
Fix from $1,950 2024-06-27
Chuanhuchatgpt HIGH 7.5
CVE-2024-6090

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This v…

Patch available
Fix from $1,950 2024-06-27
Pytorch Lightning CRITICAL 9.8
CVE-2024-5980

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.…

Fix: 2.3.3+
Fix from $2,300 2024-06-27
Unclassified HIGH 7.4
CVE-2024-5824

A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `config…

Patch available
Fix from $1,950 2024-06-27
Devika HIGH 7.5
CVE-2024-5548

A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can …

Patch available
Fix from $1,950 2024-06-27
Unclassified HIGH 7.7
CVE-2024-22232

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from…

Mitigation only
Fix from $1,950 2024-06-27
Unclassified MEDIUM 5.0
CVE-2024-22231

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitr…

Mitigation only
Fix from $1,600 2024-06-27
Whatsup Gold MEDIUM 6.5
CVE-2024-5017

In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProf…

Fix: 23.1.3+
Fix from $1,600 2024-06-25
Whatsup Gold HIGH 7.5
CVE-2024-5018

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionControl…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 7.5
CVE-2024-5019

In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionContr…

Fix: 23.1.3+
Fix from $1,950 2024-06-25