Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Build Of Keycloak HIGH 8.1
CVE-2024-1132

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali…

Fix: 22.0.10 / 24.0.3+
Fix from $1,950 2024-04-17
Kohya Ss MEDIUM 5.3
CVE-2024-32023

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `find_and_replace` functio…

Fix: 24.0.1+
Fix from $1,600 2024-04-16
Kohya Ss MEDIUM 6.5
CVE-2024-32024

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `add_pre_postfix` function…

Fix: 24.0.1+
Fix from $1,600 2024-04-16
Unclassified MEDIUM 5.3
CVE-2024-31451

DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixe…

Patch available
Fix from $1,600 2024-04-16
Langchain HIGH 8.8
CVE-2024-3571

langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its L…

Patch available
Fix from $1,950 2024-04-16
Mlflow CRITICAL 9.3
CVE-2024-3573

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary fil…

Fix: 2.10.0+
Fix from $2,300 2024-04-16
Unclassified HIGH 8.8
CVE-2024-1961

vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. A…

Mitigation only
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1593

A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequenc…

Fix: 2.11.3+
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1594

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when cre…

Fix: 2.11.3+
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1483

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a serie…

Fix: 2.12.1+
Fix from $1,950 2024-04-16
Mlflow HIGH 7.5
CVE-2024-1558

A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to i…

Fix: 2.12.1+
Fix from $1,950 2024-04-16
Mlflow HIGH 8.1
CVE-2024-1560

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass …

Fix: after 2.9.2
Fix from $1,950 2024-04-16
Wbsairback MEDIUM 6.5
CVE-2024-3783

The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files…

Mitigation only
Fix from $1,600 2024-04-15
Unclassified MEDIUM 5.5
CVE-2023-52144

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Prod…

Mitigation only
Fix from $1,600 2024-04-15
Nginxwebui CRITICAL 9.8
CVE-2024-3737

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery o…

Fix: 4.2.4+
Fix from $2,300 2024-04-13
Unclassified MEDIUM 6.3
CVE-2024-31462

stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a lim…

Patch available
Fix from $1,600 2024-04-12
Unclassified HIGH 8.2
CVE-2024-32005

NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource file…

Patch available
Fix from $1,950 2024-04-12
Dedecms HIGH 7.5
CVE-2024-3686

A vulnerability has been found in DedeCMS 5.7.112-UTF8 and classified as problematic. Affected by this vulnerability is an unknown functionality of t…

No fix yet
Fix from $1,950 2024-04-12
Derbynet CRITICAL 9.8
CVE-2024-31818

Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php compon…

No fix yet
Fix from $2,300 2024-04-12
Secure Lockdown MEDIUM 6.5
CVE-2024-29502

An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths.

No fix yet
Fix from $1,600 2024-04-10
Qdrant CRITICAL 9.8
CVE-2024-2221

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint…

Patch available
Fix from $2,300 2024-04-10
Gradio HIGH 7.5
CVE-2024-1728EPSS 85%

gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton compone…

Fix: 4.19.2+
Fix from $1,950 2024-04-10
Lollms Web Ui CRITICAL 9.8
CVE-2024-1511

The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This …

No fix yet
Fix from $2,300 2024-04-10
Media Library Folders MEDIUM 6.5
CVE-2024-31287

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects …

Fix: 8.1.9+
Fix from $1,600 2024-04-10
Wp Poll Maker HIGH 8.1
CVE-2024-31240

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Ma…

Fix: 3.4+
Fix from $1,950 2024-04-10
File Manager MEDIUM 6.8
CVE-2024-2654

The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup fun…

Fix: 7.2.6+
Fix from $1,600 2024-04-09
Ht Mega MEDIUM 6.5
CVE-2024-1974

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via…

Fix: 2.4.7+
Fix from $1,600 2024-04-09
Unclassified HIGH 7.7
CVE-2024-31457

gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversio…

Patch available
Fix from $1,950 2024-04-09
Defender For Iot HIGH 8.8
CVE-2024-29053

Microsoft Defender for IoT Remote Code Execution Vulnerability

Fix: 24.1.3+
Fix from $1,950 2024-04-09
Fortisandbox HIGH 8.1
CVE-2024-23671

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSan…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2024-04-09