Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Filecatalyst Direct MEDIUM 5.3
CVE-2024-25154

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to retur…

Fix: 3.8.9+
Fix from $1,600 2024-03-13
Pulsar CRITICAL 9.9
CVE-2024-27317EPSS 57%

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Confidental Containers CRITICAL 9.0
CVE-2024-21400

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Fix: 0.3.3+
Fix from $2,300 2024-03-12
Monitool MEDIUM 6.5
CVE-2024-1303

Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vu…

Fix: 4.7+
Fix from $1,600 2024-03-12
A Blog Cms MEDIUM 6.5
CVE-2024-27279

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x se…

Fix: after 3.1.9
Fix from $1,600 2024-03-12
Unclassified HIGH 7.2
CVE-2024-27121

Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the …

Mitigation only
Fix from $1,950 2024-03-12
Zkbio Media HIGH 7.5
CVE-2024-2318

A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of …

Mitigation only
Fix from $1,950 2024-03-08
macOS HIGH 7.1
CVE-2024-23216

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. …

Fix: 12.7.4 / 13.6.5+
Fix from $1,950 2024-03-08
Paddlepaddle CRITICAL 9.1
CVE-2024-0818

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

Fix: 2.6.0+
Fix from $2,300 2024-03-07
Netbackup CRITICAL 9.8
CVE-2024-28222

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenti…

Fix: 3.1.2 / 8.1.2+
Fix from $2,300 2024-03-07
Jeewms HIGH 7.5
CVE-2024-27765

Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateControlle…

Fix: after 3.7
Fix from $1,950 2024-03-05
Jeewms CRITICAL 9.8
CVE-2024-27764

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

Fix: after 3.7
Fix from $2,300 2024-03-05
Arubaos CRITICAL 9.1
CVE-2024-25614

There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to…

Fix: 8.10.0.10 / 8.11.2.1+
Fix from $2,300 2024-03-05
Idurar HIGH 7.5
CVE-2024-25164

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionali…

No fix yet
Fix from $1,950 2024-03-05
Teamcity HIGH 7.3
CVE-2024-27199 KEVEPSS 100%

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Fix: 2023.11.4+
Fix from $1,950 2024-03-04
Langchain HIGH 8.1
CVE-2024-28088

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call.…

Fix: 0.1.12+
Fix from $1,950 2024-03-04
Product Designer HIGH 7.5
CVE-2024-24307

Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attack…

Fix: 1.178.36+
Fix from $1,950 2024-03-03
Unclassified HIGH 8.8
CVE-2024-25386

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code…

Mitigation only
Fix from $1,950 2024-03-01
Filenet Content Manager MEDIUM 5.3
CVE-2023-38366

IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacke…

Mitigation only
Fix from $1,600 2024-03-01
Session MEDIUM 5.5
CVE-2024-2045

Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possi…

No fix yet
Fix from $1,600 2024-03-01
Datacube3 Firmware CRITICAL 9.8
CVE-2024-25830EPSS 24%

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker…

No fix yet
Fix from $2,300 2024-02-29
Xenforo HIGH 8.1
CVE-2024-25006

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZI…

Fix: 2.2.14+
Fix from $1,950 2024-02-29
Ofbiz CRITICAL 9.1
CVE-2024-25065EPSS 48%

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $2,300 2024-02-29
Ofbiz MEDIUM 5.3
CVE-2024-23946

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $1,600 2024-02-29
Blesta HIGH 7.1
CVE-2024-25859

A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbi…

Fix: 5.9.2+
Fix from $1,950 2024-02-28
Anythingllm HIGH 8.1
CVE-2024-0763

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would …

Fix: 1.0.0+
Fix from $1,950 2024-02-27
Fedora HIGH 7.5
CVE-2024-25711

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclos…

Fix: 256+
Fix from $1,950 2024-02-27
Esphome HIGH 8.8
CVE-2024-27081

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHo…

Patch available
Fix from $1,950 2024-02-26
Webos Signage HIGH 8.8
CVE-2024-1886

This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

Mitigation only
Fix from $1,950 2024-02-26
Brizy MEDIUM 6.5
CVE-2024-1165

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This ma…

Fix: 2.4.40+
Fix from $1,600 2024-02-26