Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Lollms Web Ui HIGH 7.5
CVE-2024-2548

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_b…

Fix: 9.5+
Fix from $1,950 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2624

A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/swit…

Fix: 9.4+
Fix from $2,300 2024-06-06
Mlflow HIGH 7.5
CVE-2024-2928EPSS 22%

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vu…

Fix: 2.11.3+
Fix from $1,950 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2360

parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplie…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.1
CVE-2024-2362

A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths betw…

No fix yet
Fix from $2,300 2024-06-06
Unclassified MEDIUM 6.3
CVE-2024-23793

The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or custome…

Mitigation only
Fix from $1,600 2024-06-06
Mlflow HIGH 8.8
CVE-2024-0520

A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS comm…

Fix: 2.9.0+
Fix from $1,950 2024-06-06
Lollms Web Ui CRITICAL 9.1
CVE-2024-1873EPSS 13%

parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0.…

Patch available
Fix from $2,300 2024-06-06
Prosafe Network Management System HIGH 8.8
CVE-2024-5505EPSS 47%

NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote att…

Fix: 1.7.0.37+
Fix from $1,950 2024-06-06
Gradio HIGH 7.5
CVE-2024-4941

A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input val…

Fix: 4.31.4+
Fix from $1,950 2024-06-06
Deep Java Library HIGH 8.8
CVE-2024-2914

A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vulnerability allows an attacke…

Patch available
Fix from $1,950 2024-06-06
Cubecart CRITICAL 9.8
CVE-2024-34832EPSS 5%

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g a…

Fix: 6.5.5+
Fix from $2,300 2024-06-06
Serv U HIGH 7.5
CVE-2024-28995 KEVEPSS 100%

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Fix: 15.4.2+
Fix from $1,950 2024-06-06
Startklar Elmentor Addons CRITICAL 9.8
CVE-2024-5153

The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzo…

Fix: after 1.7.15
Fix from $2,300 2024-06-06
Cowidgets Elementor Addons HIGH 8.8
CVE-2024-5179

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item…

Fix: 1.2.0+
Fix from $1,950 2024-06-06
Stockholm CRITICAL 9.8
CVE-2024-34551

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusi…

Fix: 9.7+
Fix from $2,300 2024-06-04
Stockholm HIGH 8.8
CVE-2024-34552

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusi…

Fix: 9.7+
Fix from $1,950 2024-06-04
Stockholm Core HIGH 8.8
CVE-2024-34554

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm Core allows PHP Local File In…

Fix: 2.4.2+
Fix from $1,950 2024-06-04
Element Pack MEDIUM 6.5
CVE-2024-33568

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element P…

Fix: after 7.7.4
Fix from $1,600 2024-06-04
Unclassified HIGH 8.8
CVE-2024-33628

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This …

Mitigation only
Fix from $1,950 2024-06-04
Sina Extension For Elementor HIGH 8.8
CVE-2024-34384

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension for Elementor allows PHP Loc…

Fix: 3.5.2+
Fix from $1,950 2024-06-04
Unclassified CRITICAL 9.0
CVE-2024-33560

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This is…

Mitigation only
Fix from $2,300 2024-06-04
Better Elementor Addons MEDIUM 6.5
CVE-2024-33541

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elementor Addons allows PHP Local…

Fix: 1.4.2+
Fix from $1,600 2024-06-04
Xstore Core HIGH 8.8
CVE-2024-33557

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.Th…

Fix: 5.3.9+
Fix from $1,950 2024-06-04
Ofbiz CRITICAL 9.1
CVE-2024-36104EPSS 87%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…

Fix: 18.12.14+
Fix from $2,300 2024-06-04
Devicehub CRITICAL 9.8
CVE-2024-27776

MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE

Mitigation only
Fix from $2,300 2024-06-02
Ollama HIGH 8.8
CVE-2024-37032EPSS 90%

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the Test…

Fix: 0.1.34+
Fix from $1,950 2024-05-31
Zkbio Cvsecurity HIGH 7.1
CVE-2024-35428

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server wh…

No fix yet
Fix from $1,950 2024-05-30
Zkbio Cvsecurity MEDIUM 6.5
CVE-2024-35429

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

No fix yet
Fix from $1,600 2024-05-30
Unclassified HIGH 8.1
CVE-2024-36267

Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, a logged-in user may obtain o…

Mitigation only
Fix from $1,950 2024-05-30