Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified CRITICAL 9.8
CVE-2024-27174

Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities …

No fix yet
Fix from $2,300 2024-06-14
Unclassified CRITICAL 9.8
CVE-2024-27144

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure file…

Mitigation only
Fix from $2,300 2024-06-14
Unclassified CRITICAL 9.8
CVE-2024-27145

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An …

Mitigation only
Fix from $2,300 2024-06-14
Omni Cms MEDIUM 5.3
CVE-2023-35860

A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information…

Mitigation only
Fix from $1,600 2024-06-13
Acrobat Reader HIGH 7.5
CVE-2024-34129

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path T…

Fix: 24.5.0.33694+
Fix from $1,950 2024-06-13
Ebx MEDIUM 5.3
CVE-2024-4576

The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthoriz…

Fix: after 5.9.25
Fix from $1,600 2024-06-13
Sage Rtu Firmware HIGH 8.1
CVE-2024-37037

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user wi…

Patch available
Fix from $1,950 2024-06-12
Cri O HIGH 8.1
CVE-2024-5154

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw…

Mitigation only
Fix from $1,950 2024-06-12
Unclassified CRITICAL 9.1
CVE-2024-4315

parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoi…

Patch available
Fix from $2,300 2024-06-12
Unclassified MEDIUM 5.3
CVE-2024-37169

@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Play…

Patch available
Fix from $1,600 2024-06-10
Suitecrm HIGH 8.8
CVE-2024-36418

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connec…

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Ovic Importer MEDIUM 6.5
CVE-2024-35754

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This is…

Fix: after 1.6.3
Fix from $1,600 2024-06-10
Sc Filechecker MEDIUM 6.5
CVE-2024-35743

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Siteclean SC filechecker allows Path Traversal, File …

Fix: after 0.6
Fix from $1,600 2024-06-10
Upunzipper MEDIUM 6.5
CVE-2024-35744

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upunzipper allows Path Traversal,…

Fix: after 1.0.0
Fix from $1,600 2024-06-10
Strategery Migrations HIGH 7.5
CVE-2024-35745

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Gabriel Somoza / Joseph Fitzgibbons Strategery Migrat…

Fix: after 1.0
Fix from $1,950 2024-06-10
Checkout Field Editor For Woocommerce CRITICAL 9.1
CVE-2024-35658

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro)…

Fix: 3.6.3+
Fix from $2,300 2024-06-10
Mega Menu CRITICAL 9.8
CVE-2024-35677

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusi…

Fix: 2.3.13+
Fix from $2,300 2024-06-10
Unclassified MEDIUM 6.5
CVE-2024-35474

A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server, via setP…

Mitigation only
Fix from $1,600 2024-06-10
Unclassified CRITICAL 9.9
CVE-2024-34762

Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne…

Mitigation only
Fix from $2,300 2024-06-10
Arforms HIGH 8.1
CVE-2024-32703

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects …

Fix: 6.4.1+
Fix from $1,950 2024-06-09
Contest Gallery HIGH 8.1
CVE-2024-32778

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest G…

Fix: 21.3.5+
Fix from $1,950 2024-06-09
Market Exporter HIGH 8.1
CVE-2024-5637

The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_files' function …

Fix: 2.0.20+
Fix from $1,950 2024-06-07
Photo Gallery HIGH 8.8
CVE-2024-5481

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including,…

Fix: 1.8.24+
Fix from $1,950 2024-06-07
H2o MEDIUM 5.3
CVE-2024-5550

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulne…

No fix yet
Fix from $1,600 2024-06-06
Onnx HIGH 8.8
CVE-2024-5187

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due t…

No fix yet
Fix from $1,950 2024-06-06
Lollms HIGH 7.5
CVE-2024-4881

A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in vers…

Fix: 5.9.0+
Fix from $1,950 2024-06-06
Lollms CRITICAL 9.8
CVE-2024-3429EPSS 28%

A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` f…

Fix: 9.6+
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-4320EPSS 34%

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…

No fix yet
Fix from $2,300 2024-06-06
Chuanhuchatgpt CRITICAL 9.8
CVE-2024-3234

The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application i…

Fix: 20240305+
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-3322

A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5…

Fix: 9.5+
Fix from $2,300 2024-06-06