Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.1
CVE-2024-0980

The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.

No fix yet
Fix from $1,950 2024-03-28
Access Management CRITICAL 9.8
CVE-2023-0582

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa…

Fix: 7.1.4+
Fix from $2,300 2024-03-27
Unclassified CRITICAL 9.1
CVE-2024-28335

Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory,…

Patch available
Fix from $2,300 2024-03-27
The Plus Addons For Elementor HIGH 8.8
CVE-2024-2203

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clie…

Fix: 5.4.2+
Fix from $1,950 2024-03-27
The Plus Addons For Elementor MEDIUM 6.4
CVE-2024-2210

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team…

Fix: 5.4.2+
Fix from $1,600 2024-03-27
Unclassified HIGH 7.5
CVE-2024-25136

There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the co…

Mitigation only
Fix from $1,950 2024-03-26
Linux Kernel MEDIUM 5.5
CVE-2023-52623

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning whi…

Fix: 4.19.307 / 5.4.269+
Fix from $1,600 2024-03-26
Client Connector HIGH 7.8
CVE-2023-41973

ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName …

Fix: 4.3.0.121+
Fix from $1,950 2024-03-26
Lg Led Assistant CRITICAL 9.8
CVE-2024-2863EPSS 64%

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

Mitigation only
Fix from $2,300 2024-03-25
Identityiq HIGH 7.5
CVE-2024-2227

This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (…

Fix: 8.1+
Fix from $1,950 2024-03-22
Diaenergie HIGH 8.8
CVE-2024-25567

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that …

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Diaenergie HIGH 8.1
CVE-2024-28171

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the…

Fix: 1.10.00.005+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-27921EPSS 61%

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior …

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Webpack Dev Middleware HIGH 7.5
CVE-2024-29180

Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address s…

Fix: 5.3.4 / 6.1.2+
Fix from $1,950 2024-03-21
Unclassified MEDIUM 5.4
CVE-2024-1142

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted requ…

Mitigation only
Fix from $1,600 2024-03-21
Vigor3910 Firmware HIGH 7.5
CVE-2024-23721

A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the fu…

Fix: after 4.3.2.5
Fix from $1,950 2024-03-20
Geoserver HIGH 7.2
CVE-2023-41877

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in ve…

Fix: after 2.23.4
Fix from $1,950 2024-03-20
Confluence Data Center HIGH 8.8
CVE-2024-21677

This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a…

Fix: 7.19.20 / 8.5.7+
Fix from $1,950 2024-03-19
Openclinic Ga HIGH 7.5
CVE-2023-40279

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main…

No fix yet
Fix from $1,950 2024-03-19
Unclassified HIGH 8.8
CVE-2024-24042

Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirect in Ru…

Patch available
Fix from $1,950 2024-03-19
Unclassified MEDIUM 5.5
CVE-2024-24043

Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file.

Patch available
Fix from $1,600 2024-03-19
Openclinic Ga HIGH 7.5
CVE-2023-40280

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popu…

No fix yet
Fix from $1,950 2024-03-19
Unilogic CRITICAL 9.8
CVE-2024-27768

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

Fix: 1.35.227+
Fix from $2,300 2024-03-18
Unilogic HIGH 8.8
CVE-2024-27770

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal

Fix: 1.35.227+
Fix from $1,950 2024-03-18
Unilogic HIGH 8.8
CVE-2024-27771

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

Fix: 1.35.227+
Fix from $1,950 2024-03-18
Unclassified HIGH 7.5
CVE-2023-40747

Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. If this v…

Mitigation only
Fix from $1,950 2024-03-18
Goanywhere Managed File Transfer MEDIUM 6.5
CVE-2024-25156

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th…

Fix: 7.4.2+
Fix from $1,600 2024-03-14
Wings HIGH 8.5
CVE-2024-27102

Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability …

Fix: 1.11.9+
Fix from $1,950 2024-03-13
Elementor Addon Elements MEDIUM 6.5
CVE-2024-1358

The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render f…

Fix: 1.13+
Fix from $1,600 2024-03-13
File Manager CRITICAL 9.9
CVE-2023-6825EPSS 6%

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (fre…

Fix: after 8.3.4
Fix from $2,300 2024-03-13