Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Ifair HIGH 7.5
CVE-2024-22523

Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage …

Fix: after 23.8_ad0
Fix from $1,950 2024-01-30
Fedora HIGH 7.5
CVE-2024-23334EPSS 77%

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it …

Fix: 3.9.2+
Fix from $1,950 2024-01-29
Gotham Blackbird Witchcraft MEDIUM 6.5
CVE-2023-30970

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …

Fix: 1.1.0 / 103.30230304.433+
Fix from $1,600 2024-01-29
Thruk CRITICAL 9.8
CVE-2024-23822

Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form …

Fix: 3.12+
Fix from $2,300 2024-01-29
Nginx Ui CRITICAL 9.8
CVE-2024-23827

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does n…

Mitigation only
Fix from $2,300 2024-01-29
Kuerp CRITICAL 9.8
CVE-2024-0989

A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the fu…

Fix: after 1.0.4
Fix from $2,300 2024-01-29
GitLab CRITICAL 9.9
CVE-2024-0402

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which a…

Fix: 16.5.8 / 16.6.6+
Fix from $2,300 2024-01-26
Avalanche MEDIUM 6.5
CVE-2023-41474EPSS 38%

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.…

No fix yet
Fix from $1,600 2024-01-25
Linkwechat HIGH 7.5
CVE-2024-0882

A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-…

No fix yet
Fix from $1,950 2024-01-25
Atril HIGH 7.8
CVE-2023-52076

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerabili…

Fix: 1.26.2+
Fix from $1,950 2024-01-25
Jenkins CRITICAL 9.8
CVE-2024-23897 KEVEPSS 100%

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a …

Fix: 2.426.3 / 2.442+
Fix from $2,300 2024-01-24
Git Server MEDIUM 6.5
CVE-2024-23899

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed b…

Fix: after 99.va_0826a_b_cdfa_d
Fix from $1,600 2024-01-24
Log Command HIGH 7.5
CVE-2024-23904

Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path …

Fix: after 1.0.2
Fix from $1,950 2024-01-24
Whoogle Search MEDIUM 5.3
CVE-2024-22204

Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in…

Fix: 0.8.4+
Fix from $1,600 2024-01-23
A Blog Cms HIGH 8.1
CVE-2024-23182

Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.…

Fix: 2.10.50 / 2.11.58+
Fix from $1,950 2024-01-23
Node Server MEDIUM 5.3
CVE-2024-23340

@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request objec…

Fix: 1.4.1+
Fix from $1,600 2024-01-22
Sysmac Studio HIGH 7.8
CVE-2022-45792

Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overw…

Fix: 1.54.0+
Fix from $1,950 2024-01-22
Autolab MEDIUM 6.5
CVE-2023-44395

Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path trav…

Fix: 2.12.0+
Fix from $1,600 2024-01-22
Dremio HIGH 8.8
CVE-2024-23768

Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folde…

Fix: 22.2.3 / 23.2.4+
Fix from $1,950 2024-01-22
Dir 859 Firmware CRITICAL 9.8
CVE-2024-0769 KEVEPSS 83%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some un…

Mitigation only
Fix from $2,300 2024-01-21
Sterling Control Center MEDIUM 5.3
CVE-2023-35020

IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…

Patch available
Fix from $1,600 2024-01-19
Language Server Protocol Integration CRITICAL 9.8
CVE-2024-22415

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve…

Fix: 2.2.2+
Fix from $2,300 2024-01-18
Workforce Access MEDIUM 5.5
CVE-2023-5097

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

Fix: 8.7+
Fix from $1,600 2024-01-16
Fox Currency Switcher Professional For Woocommerce HIGH 8.8
CVE-2021-24566

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Fix: 1.3.7+
Fix from $1,950 2024-01-16
Essential Blocks CRITICAL 9.8
CVE-2023-6623EPSS 51%

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templat…

Fix: 4.4.3+
Fix from $2,300 2024-01-15
Shiro MEDIUM 6.5
CVE-2023-46749

Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe…

Fix: 1.13.0+
Fix from $1,600 2024-01-15
Airpass HIGH 7.5
CVE-2023-48383

NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can e…

Mitigation only
Fix from $1,950 2024-01-15
Flaskcode HIGH 7.5
CVE-2023-52288

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to …

Fix: after 0.0.8
Fix from $1,950 2024-01-13
Flaskcode HIGH 7.5
CVE-2023-52289

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to…

Fix: after 0.0.8
Fix from $1,950 2024-01-13
Openscape Voice HIGH 7.5
CVE-2023-48166

A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to vie…

Mitigation only
Fix from $1,950 2024-01-12