Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unify Openscape Xpressions Webassistant CRITICAL 9.8
CVE-2023-40266

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

Fix: 7r1_fr5_hf42_p911+
Fix from $2,300 2024-02-08
Multilingual And Multistore Sitemap Pro HIGH 7.5
CVE-2024-24311

Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6…

Fix: 1.6.6+
Fix from $1,950 2024-02-07
Desktop MEDIUM 5.0
CVE-2024-0849

Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.

Mitigation only
Fix from $1,600 2024-02-07
Agent Dvr HIGH 8.8
CVE-2024-22514

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

Mitigation only
Fix from $1,950 2024-02-06
Clearml HIGH 8.8
CVE-2024-24591

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset …

Fix: after 1.14.1
Fix from $1,950 2024-02-06
Teamcity MEDIUM 5.3
CVE-2024-24942EPSS 32%

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

Fix: 2023.11.3+
Fix from $1,600 2024-02-06
Teamcity MEDIUM 5.3
CVE-2024-24938

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

Fix: 2023.11.2+
Fix from $1,600 2024-02-06
Sling Servlets Resolver HIGH 7.5
CVE-2024-23673

Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli…

Fix: 2.11.0+
Fix from $1,950 2024-02-06
Dashboards.php CRITICAL 9.8
CVE-2024-24398

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via…

Fix: 2024.1.2+
Fix from $2,300 2024-02-06
Gradio CRITICAL 9.4
CVE-2024-0964

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

Patch available
Fix from $2,300 2024-02-05
Photo Gallery HIGH 7.2
CVE-2024-0221

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu…

Fix: 1.8.20+
Fix from $1,950 2024-02-05
Shield Security CRITICAL 9.8
CVE-2023-6989EPSS 57%

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions u…

Fix: 18.5.10+
Fix from $2,300 2024-02-05
Engrampa CRITICAL 9.6
CVE-2023-52138

Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged t…

Fix: 1.26.2+
Fix from $2,300 2024-02-05
Enterprise Linux MEDIUM 5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…

No fix yet
Fix from $1,600 2024-02-05
Nec E705 Firmware CRITICAL 9.8
CVE-2023-7077

Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705,…

Mitigation only
Fix from $2,300 2024-02-05
Lantime Firmware HIGH 7.2
CVE-2021-46902

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validati…

Fix: 6.24.029 / 7.04.008+
Fix from $1,950 2024-02-04
Ai Popup HIGH 7.2
CVE-2024-0844

The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChan…

Fix: 2.2.5+
Fix from $1,950 2024-02-02
Chart Fx HIGH 7.5
CVE-2023-39611

An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted w…

No fix yet
Fix from $1,950 2024-02-02
Liveconfig HIGH 7.5
CVE-2024-22851

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the …

Fix: 2.5.2+
Fix from $1,950 2024-02-02
Automation Studio HIGH 7.5
CVE-2021-22281

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation S…

Fix: after 4.12
Fix from $1,950 2024-02-02
Apktool CRITICAL 9.8
CVE-2024-24482

Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.

Fix: 2.9.3+
Fix from $2,300 2024-02-02
Soar Qradar Plugin App MEDIUM 6.5
CVE-2023-38019

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially …

Fix: 5.0.3+
Fix from $1,600 2024-02-02
Serverrpexposer CRITICAL 9.8
CVE-2024-22779

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerP…

Fix: after 1.0.2
Fix from $2,300 2024-02-02
Rapid Scada MEDIUM 6.5
CVE-2024-22096

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a sp…

Fix: after 5.8.4
Fix from $1,600 2024-02-02
Crafatar HIGH 7.5
CVE-2024-24756

Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested f…

Fix: 2.1.5+
Fix from $1,950 2024-02-01
Rapid Scada HIGH 8.8
CVE-2024-21852

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vu…

Fix: after 5.8.4
Fix from $1,950 2024-02-01
Buildkit CRITICAL 9.1
CVE-2024-23652

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend …

Fix: 0.12.5+
Fix from $2,300 2024-01-31
Controledge Unit Operations Controller Firmware MEDIUM 5.3
CVE-2023-5390

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlE…

Mitigation only
Fix from $1,600 2024-01-31
Stereoscope CRITICAL 9.8
CVE-2024-24579

stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an O…

Fix: 0.0.1+
Fix from $2,300 2024-01-31
Cratedb MEDIUM 6.5
CVE-2024-24565

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function i…

Fix: 5.3.9 / 5.4.8+
Fix from $1,600 2024-01-30