Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Kraken HIGH 7.5
CVE-2022-47747

kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.

Fix: after 0.1.4
Fix from $1,950 2023-01-20
Reprise License Manager HIGH 8.1
CVE-2021-37500

Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users wit…

Fix: 16.0+
Fix from $1,950 2023-01-20
Sma1000 Firmware HIGH 7.5
CVE-2023-0126EPSS 73%

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary file…

Mitigation only
Fix from $1,950 2023-01-19
Nodeserver HIGH 7.5
CVE-2020-36651

A vulnerability has been found in youngerheart nodeserver and classified as critical. Affected by this vulnerability is an unknown functionality of t…

Fix: 2020-08-21+
Fix from $1,950 2023-01-18
Ms 3000 Firmware HIGH 7.5
CVE-2022-43975

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server a…

Fix: 3.7.6.25p0_3.2.2.17p0_4.7p0+
Fix from $1,950 2023-01-17
Equipment Predictive Maintenance MEDIUM 6.5
CVE-2022-2893

RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and downlo…

Mitigation only
Fix from $1,600 2023-01-17
Faplanet CRITICAL 9.8
CVE-2014-125080

A vulnerability has been found in frontaccounting faplanet and classified as critical. This vulnerability affects unknown code. The manipulation lead…

Fix: 2014-05-21+
Fix from $2,300 2023-01-16
Jekbox HIGH 7.5
CVE-2016-15019

A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. Th…

Fix: 2016-02-01+
Fix from $1,950 2023-01-15
Apollo HIGH 8.8
CVE-2015-10043

A vulnerability, which was classified as critical, was found in abreen Apollo. This affects an unknown part. The manipulation of the argument file le…

Fix: 2015-01-29+
Fix from $1,950 2023-01-14
Autolab MEDIUM 6.5
CVE-2022-41956

Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer au…

Fix: 2.10.0+
Fix from $1,600 2023-01-14
Awesome Procedures On Cyper MEDIUM 6.5
CVE-2022-23532

APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path traversal vulnerability…

Fix: 4.3.0.12 / 4.4.0.12+
Fix from $1,600 2023-01-14
Mailenable HIGH 8.8
CVE-2022-42136

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission …

Fix: 8.66 / 9.85+
Fix from $1,950 2023-01-13
Webbrowser CRITICAL 9.8
CVE-2022-45299

An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.

Fix: 0.8.3+
Fix from $2,300 2023-01-13
Fileorbis HIGH 7.5
CVE-2022-3693

Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Managem…

Fix: 10.6.3+
Fix from $1,950 2023-01-13
Keycloak CRITICAL 9.1
CVE-2022-3782EPSS 6%

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…

Mitigation only
Fix from $2,300 2023-01-13
Bmc HIGH 7.8
CVE-2022-42287

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Bmc HIGH 7.8
CVE-2022-42280

NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authent…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Bmc MEDIUM 5.5
CVE-2022-42282

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosur…

Fix: 00.19.07+
Fix from $1,600 2023-01-13
Jefferson MEDIUM 5.9
CVE-2022-4885

A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unknown code of the file src/scri…

Fix: 0.4+
Fix from $1,600 2023-01-11
Nostromo CRITICAL 9.8
CVE-2022-48253

nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vu…

Fix: 2.1+
Fix from $2,300 2023-01-11
Acr1000a R R2 Firmware HIGH 7.5
CVE-2022-4636

Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path travers…

Patch available
Fix from $1,950 2023-01-10
Media Upload CRITICAL 9.8
CVE-2016-15017

A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileLi…

Fix: 0.9.0+
Fix from $2,300 2023-01-10
Automation License Manager CRITICAL 9.8
CVE-2022-43514

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), Te…

Mitigation only
Fix from $2,300 2023-01-10
Sinec Ins HIGH 8.8
CVE-2022-45092EPSS 31%

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…

Fix: 1.0+
Fix from $1,950 2023-01-10
Sinec Ins HIGH 8.8
CVE-2022-45093

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Ma…

Fix: 1.0+
Fix from $1,950 2023-01-10
Openam HIGH 7.5
CVE-2023-22320

OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(C…

Mitigation only
Fix from $1,950 2023-01-10
Zoom HIGH 7.1
CVE-2022-36928

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and…

Fix: 5.13.0+
Fix from $1,950 2023-01-09
Maps Js Icoads MEDIUM 5.3
CVE-2014-125068

A vulnerability was found in saxman maps-js-icoads and classified as critical. This issue affects some unknown processing of the file http-server.js.…

Fix: 09-02-2014+
Fix from $1,600 2023-01-08
Maps Js Icoads MEDIUM 5.3
CVE-2014-125069

A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to…

Fix: 09-02-2014+
Fix from $1,600 2023-01-08
Surpass MEDIUM 5.3
CVE-2015-10030

A vulnerability has been found in SUKOHI Surpass and classified as critical. This vulnerability affects unknown code of the file src/Sukohi/Surpass/S…

Fix: 1.0.0+
Fix from $1,600 2023-01-08