Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Jefferson MEDIUM 5.5
CVE-2023-0592

A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to …

Fix: 0.4.1+
Fix from $1,600 2023-01-31
Yaffshiv MEDIUM 5.5
CVE-2023-0593

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to w…

Fix: after 0.1
Fix from $1,600 2023-01-31
Megaservisignadapter HIGH 7.5
CVE-2022-39059

ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker c…

Fix: 1.0.22.1004+
Fix from $1,950 2023-01-31
Ecostruxure Power Commission CRITICAL 9.8
CVE-2022-0223

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create …

Fix: 2.22+
Fix from $2,300 2023-01-30
Ecostruxure Power Commission CRITICAL 9.8
CVE-2022-22731

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attac…

Fix: 2.22+
Fix from $2,300 2023-01-30
Freshtomato HIGH 7.5
CVE-2022-38451

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to …

No fix yet
Fix from $1,950 2023-01-30
Servst HIGH 7.5
CVE-2022-25936

Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.

Fix: 2.0.3+
Fix from $1,950 2023-01-30
Jszip HIGH 7.3
CVE-2022-48285

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

Fix: 3.8.0+
Fix from $1,950 2023-01-29
Netmatch S Ci HIGH 7.5
CVE-2022-39812

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to …

No fix yet
Fix from $1,950 2023-01-27
Pandora Fms CRITICAL 9.8
CVE-2022-43979

There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha…

Fix: 766+
Fix from $2,300 2023-01-27
Sage Frp 1000 HIGH 7.5
CVE-2019-25053

A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of …

Fix: 2019-11+
Fix from $1,950 2023-01-27
Magento HIGH 7.2
CVE-2021-41143

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Glassfish HIGH 7.5
CVE-2022-2712

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting wi…

Fix: after 6.2.5
Fix from $1,950 2023-01-27
Debian Linux MEDIUM 5.7
CVE-2022-47951

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and …

Fix: 20.0.2 / 23.0.1+
Fix from $1,600 2023-01-26
Quartz Gold Firmware MEDIUM 6.5
CVE-2022-41154

A directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafte…

No fix yet
Fix from $1,600 2023-01-26
Quartz Gold Firmware HIGH 8.1
CVE-2022-40701

A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted …

No fix yet
Fix from $1,950 2023-01-26
Quartz Gold Firmware HIGH 8.8
CVE-2022-39045

A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP reque…

No fix yet
Fix from $1,950 2023-01-26
Quartz Gold Firmware MEDIUM 6.5
CVE-2022-38088

A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted…

No fix yet
Fix from $1,600 2023-01-26
Hl7 Fhir Core HIGH 8.1
CVE-2023-24057

HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a cra…

Fix: 1.2.30 / 5.6.92+
Fix from $1,950 2023-01-26
Binwalk HIGH 7.8
CVE-2022-4510EPSS 22%

A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyst…

Fix: 2.3.3+
Fix from $1,950 2023-01-26
Business Automation Workflow HIGH 7.5
CVE-2022-43864

IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craft…

Fix: after 21.0.3.1
Fix from $1,950 2023-01-26
Vrealize Log Insight CRITICAL 9.8
CVE-2022-31706EPSS 87%

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system…

Fix: 8.10.2+
Fix from $2,300 2023-01-26
My Cloud Pr2100 Firmware CRITICAL 9.8
CVE-2022-29844EPSS 36%

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read an…

Fix: 5.26.119+
Fix from $2,300 2023-01-26
Onnx HIGH 7.5
CVE-2022-25882

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to th…

Fix: 1.13.0+
Fix from $1,950 2023-01-26
Serve Lite HIGH 7.5
CVE-2022-21192

All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employ…

No fix yet
Fix from $1,950 2023-01-26
Gpn2.4p21 C Cn Firmware CRITICAL 9.1
CVE-2020-18331

Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform G…

No fix yet
Fix from $2,300 2023-01-26
Gpn2.4p21 C Cn Firmware CRITICAL 9.1
CVE-2020-18330

An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(…

No fix yet
Fix from $2,300 2023-01-26
Correos HIGH 7.5
CVE-2022-46639

A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.

Fix: after 1.7.8
Fix from $1,950 2023-01-23
Zdir HIGH 8.8
CVE-2023-23314

An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file.

Patch available
Fix from $1,950 2023-01-23
Act HIGH 8.8
CVE-2023-22726

act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitiz…

Fix: 0.2.40+
Fix from $1,950 2023-01-20