Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.1
CVE-2024-36427

The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or w…

Mitigation only
Fix from $1,950 2024-05-29
Teamcity MEDIUM 6.5
CVE-2024-36362

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

Fix: 2022.04.7 / 2022.10.6+
Fix from $1,600 2024-05-29
Unclassified MEDIUM 5.3
CVE-2024-5433

The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted …

Mitigation only
Fix from $1,600 2024-05-28
Datacube3 Firmware CRITICAL 9.8
CVE-2024-34854EPSS 13%

F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`

No fix yet
Fix from $2,300 2024-05-28
Douchat CRITICAL 9.8
CVE-2024-35324

Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.

No fix yet
Fix from $2,300 2024-05-28
Unclassified MEDIUM 6.5
CVE-2024-28880

Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitive infor…

Mitigation only
Fix from $1,600 2024-05-28
Unclassified HIGH 8.3
CVE-2024-35219

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an Op…

Patch available
Fix from $1,950 2024-05-27
Aj Report CRITICAL 9.8
CVE-2024-5353

A vulnerability classified as critical has been found in anji-plus AJ-Report up to 1.4.1. This affects the function decompress of the component ZIP F…

Fix: after 1.4.1
Fix from $2,300 2024-05-26
Unclassified MEDIUM 6.5
CVE-2024-36079

An issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, a temporar…

Mitigation only
Fix from $1,600 2024-05-24
Luckyframeweb HIGH 7.5
CVE-2024-35081

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.

Mitigation only
Fix from $1,950 2024-05-23
Unclassified HIGH 8.8
CVE-2024-34060

IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plug…

Patch available
Fix from $1,950 2024-05-23
Unclassified HIGH 7.2
CVE-2024-4347

The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCach…

Mitigation only
Fix from $1,950 2024-05-23
Wpzoom Elementor Addons CRITICAL 9.8
CVE-2024-5147

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,…

Fix: 1.1.38+
Fix from $2,300 2024-05-22
Unclassified MEDIUM 6.5
CVE-2024-35162

Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remo…

Mitigation only
Fix from $1,600 2024-05-22
A Blog Cms MEDIUM 6.5
CVE-2024-31394

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, …

Fix: 2.10.53 / 2.11.61+
Fix from $1,600 2024-05-22
Unclassified HIGH 7.8
CVE-2024-5040

There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory.

Mitigation only
Fix from $1,950 2024-05-21
Salon Booking System CRITICAL 9.1
CVE-2024-4442

The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the …

Fix: 10.0+
Fix from $2,300 2024-05-21
Smanga HIGH 7.5
CVE-2024-34193

smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause ar…

No fix yet
Fix from $1,950 2024-05-20
Buddyforms HIGH 7.5
CVE-2024-32830

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forg…

Fix: 2.8.9+
Fix from $1,950 2024-05-17
Husky Products Filter Professional For Woocommerce HIGH 8.8
CVE-2024-32680

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerabili…

Fix: 1.3.5.3+
Fix from $1,950 2024-05-17
Unclassified HIGH 8.5
CVE-2024-31300

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local F…

Mitigation only
Fix from $1,950 2024-05-17
Unclassified HIGH 8.0
CVE-2024-31232

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.Th…

Mitigation only
Fix from $1,950 2024-05-17
Unclassified CRITICAL 9.0
CVE-2024-31231

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.Th…

Mitigation only
Fix from $2,300 2024-05-17
Unclassified MEDIUM 6.5
CVE-2024-30509

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Artbees SellKit allows Relative Path Traversal.This i…

Mitigation only
Fix from $1,600 2024-05-17
Unclassified CRITICAL 9.3
CVE-2024-27954EPSS 73%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server …

Mitigation only
Fix from $2,300 2024-05-17
Website Builder HIGH 8.1
CVE-2024-24934

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulati…

Fix: 3.19.1+
Fix from $1,950 2024-05-17
Total Upkeep HIGH 7.5
CVE-2024-24869

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.…

Fix: 1.15.9+
Fix from $1,950 2024-05-17
Ultimate Addons For Beaver Builder MEDIUM 6.5
CVE-2023-51401

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder a…

Fix: 1.35.14+
Fix from $1,600 2024-05-17
Unclassified HIGH 7.5
CVE-2023-49753

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier System allows PHP Local File Incl…

Mitigation only
Fix from $1,950 2024-05-17
Qi Addons For Elementor HIGH 8.8
CVE-2023-47679

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addons For Elementor allows PHP L…

Fix: 1.6.4+
Fix from $1,950 2024-05-17