Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Transmission Ynh MEDIUM 5.3
CVE-2020-36647

A vulnerability classified as critical has been found in YunoHost-Apps transmission_ynh. Affected is an unknown function of the file conf/nginx.conf.…

Fix: 10-25-2020+
Fix from $1,600 2023-01-08
Larasync CRITICAL 9.8
CVE-2015-10024

A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file repository/content/file_stor…

Fix: 2015-01-20+
Fix from $2,300 2023-01-07
Openutau CRITICAL 9.8
CVE-2022-4880

A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankInstaller of the file OpenUtau.…

Fix: 0.0.991+
Fix from $2,300 2023-01-07
Qsf Portal MEDIUM 5.3
CVE-2019-25099

A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the file index.php. The manipulat…

Fix: 2019-04-29+
Fix from $1,600 2023-01-06
Jatos MEDIUM 5.3
CVE-2022-4878

A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/common/app/utils/common/ZipUtil.…

Fix: after 3.7.5
Fix from $1,600 2023-01-06
Extplorer CRITICAL 9.8
CVE-2019-25097

A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the …

Fix: 2.1.13+
Fix from $2,300 2023-01-05
Extplorer CRITICAL 9.8
CVE-2019-25098

A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknown part of the file include/ar…

Fix: 2.1.13+
Fix from $2,300 2023-01-05
Officeconnect 1820 24g Poe\+ \(185w\) Switch J9983a Firmware HIGH 7.5
CVE-2022-37934

A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerability could be remotely exploit…

Mitigation only
Fix from $1,950 2023-01-05
Amx Mod X CRITICAL 9.8
CVE-2020-36639

A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affects the function cmdVoteMap o…

Fix: 2020-05-28+
Fix from $2,300 2023-01-04
Api Management HIGH 8.6
CVE-2022-38723

Gravitee API Management before 3.15.13 allows path traversal through HTML injection.

Fix: 3.15.3+
Fix from $1,950 2023-01-03
Ziparchive HIGH 8.1
CVE-2022-36943

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArc…

Fix: after 2.5.3
Fix from $1,950 2023-01-03
Mybb HIGH 7.2
CVE-2022-45867

MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve loca…

Fix: 1.8.33+
Fix from $1,950 2023-01-03
Servisign MEDIUM 6.5
CVE-2022-46305

ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authenti…

Mitigation only
Fix from $1,600 2023-01-03
Servisign HIGH 7.8
CVE-2022-46306

ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unau…

Mitigation only
Fix from $1,950 2023-01-03
Vitals Esp MEDIUM 6.5
CVE-2022-46309

Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access…

Fix: after 6.2.0
Fix from $1,600 2023-01-03
A\+hrd HIGH 7.5
CVE-2022-39040

aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authe…

Mitigation only
Fix from $1,950 2023-01-03
Rails Cv App HIGH 7.5
CVE-2014-125033

A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/con…

Fix: 2014-11-16+
Fix from $1,950 2023-01-02
Imageserve HIGH 7.5
CVE-2017-20152

A vulnerability, which was classified as problematic, was found in aerouk imageserve. Affected is an unknown function of the file public/viewer.php o…

Patch available
Fix from $1,950 2022-12-30
Pastebinit MEDIUM 5.3
CVE-2018-25059

A vulnerability was found in pastebinit up to 0.2.2 and classified as problematic. Affected by this issue is the function pasteHandler of the file se…

Fix: after 0.2.2
Fix from $1,600 2022-12-30
Portal For Arcgis HIGH 7.5
CVE-2022-38205

In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticate…

Fix: after 10.9.1
Fix from $1,950 2022-12-29
Metersphere HIGH 8.8
CVE-2022-46178

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. V…

Fix: 2.5.1+
Fix from $1,950 2022-12-29
Streamx CRITICAL 9.8
CVE-2022-4779

StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. Stream…

Fix: after 6.04.34
Fix from $2,300 2022-12-29
Streamx MEDIUM 6.5
CVE-2022-4778

StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authenticated users to get unauthori…

Fix: after 6.04.34
Fix from $1,600 2022-12-29
Aslan Al10 Firmware HIGH 7.8
CVE-2022-44564

Huawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected system re…

Fix: after 11.1.0.10118
Fix from $1,950 2022-12-28
Arcgis Server HIGH 7.5
CVE-2022-38202

There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated …

Fix: after 10.9.1
Fix from $1,950 2022-12-28
Widoco HIGH 7.8
CVE-2022-4772

A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the file src/main/java/widoco/Widoc…

Fix: 2022-07-29+
Fix from $1,950 2022-12-27
Archiver CRITICAL 9.1
CVE-2018-25046

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc…

Fix: 2018-05-23+
Fix from $2,300 2022-12-27
Goa HIGH 7.5
CVE-2019-25073

Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended…

Fix: 1.4.3 / 2.0.10+
Fix from $1,950 2022-12-27
Aah HIGH 7.5
CVE-2020-36559

Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the targe…

Fix: 0.12.4+
Fix from $1,950 2022-12-27
Go Unzip CRITICAL 9.1
CVE-2020-36560

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc…

Fix: 1.0.0+
Fix from $2,300 2022-12-27