Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 6.5
CVE-2024-34712

Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not…

Patch available
Fix from $1,600 2024-05-14
Ruggedcom Crossbow MEDIUM 6.5
CVE-2024-27946

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the insta…

Fix: 5.5+
Fix from $1,600 2024-05-14
Dedecms HIGH 7.5
CVE-2024-4790

A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. …

Mitigation only
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.9
CVE-2024-4701EPSS 25%

A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

No fix yet
Fix from $2,300 2024-05-14
Unclassified HIGH 7.8
CVE-2024-35205

The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through ex…

Mitigation only
Fix from $1,950 2024-05-14
Dedecms MEDIUM 6.5
CVE-2024-34245

An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js…

No fix yet
Fix from $1,600 2024-05-14
macOS MEDIUM 5.5
CVE-2024-27827

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to rea…

Fix: 13.6.7 / 14.5+
Fix from $1,600 2024-05-14
Ipados MEDIUM 5.5
CVE-2024-27810

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14…

Fix: 10.5 / 12.7.5+
Fix from $1,600 2024-05-14
Dm5500 Firmware MEDIUM 6.5
CVE-2024-24908

Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A remote attacker with high pr…

Fix: 5.16.0.0+
Fix from $1,600 2024-05-08
Ofbiz CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …

Fix: 18.12.13+
Fix from $2,300 2024-05-08
Scada Data Gateway HIGH 8.8
CVE-2022-0369

Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote at…

Mitigation only
Fix from $1,950 2024-05-07
Cmseasy HIGH 7.5
CVE-2024-34315

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /ad…

No fix yet
Fix from $1,950 2024-05-07
Unclassified HIGH 7.5
CVE-2024-34523

AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traver…

Mitigation only
Fix from $1,950 2024-05-07
Unclassified CRITICAL 9.1
CVE-2024-4346

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is du…

Mitigation only
Fix from $2,300 2024-05-07
Unclassified HIGH 8.5
CVE-2024-32807

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path…

Mitigation only
Fix from $1,950 2024-05-06
Mailinspector MEDIUM 5.4
CVE-2024-34471

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.ph…

Fix: after 5.2.18
Fix from $1,600 2024-05-06
Unclassified HIGH 8.2
CVE-2024-32982

Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vu…

Patch available
Fix from $1,950 2024-05-06
Jasmin Ransomware MEDIUM 6.5
CVE-2024-30851

Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.…

No fix yet
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite HIGH 8.8
CVE-2023-51599

Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2024-05-03
Saia Pg5 Controls Suite HIGH 8.8
CVE-2023-51603

Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Mitigation only
Fix from $1,950 2024-05-03
Ignition HIGH 8.8
CVE-2023-50233

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…

Fix: 8.1.33+
Fix from $1,950 2024-05-03
Xreader HIGH 7.8
CVE-2023-44451

Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

Patch available
Fix from $1,950 2024-05-03
Advanced Core Operating System MEDIUM 6.5
CVE-2023-42129

A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose…

Fix: 5.2.1 / 6.0.2+
Fix from $1,600 2024-05-03
Advanced Core Operating System HIGH 8.8
CVE-2023-42130

A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read…

Fix: 5.2.1 / 6.0.2+
Fix from $1,950 2024-05-03
Myconnection Server HIGH 7.2
CVE-2023-42033

Visualware MyConnection Server doPostUploadfiles Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers …

Mitigation only
Fix from $1,950 2024-05-03
Supersign Media Editor HIGH 7.5
CVE-2023-40517

LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote …

Mitigation only
Fix from $1,950 2024-05-03
Supersign Media Editor MEDIUM 5.3
CVE-2023-41181

LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to di…

Mitigation only
Fix from $1,600 2024-05-03
Prosafe Network Management System HIGH 8.8
CVE-2023-41182EPSS 59%

NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker…

Fix: 1.7.0.20+
Fix from $1,950 2024-05-03
Simple Editor MEDIUM 6.5
CVE-2023-40512

LG Simple Editor PlayerController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac…

Mitigation only
Fix from $1,600 2024-05-03
Simple Editor MEDIUM 6.5
CVE-2023-40513

LG Simple Editor UserManageController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote a…

Mitigation only
Fix from $1,600 2024-05-03