Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unzip CRITICAL 9.1
CVE-2020-36561

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc…

Fix: 1.0.3-0.20200308084313-2adbaa4891b9+
Fix from $2,300 2022-12-27
Tar Utils CRITICAL 9.1
CVE-2020-36566

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc…

Fix: 0.0.0-20201201191210-20a61371de5b+
Fix from $2,300 2022-12-27
Httpserver HIGH 7.5
CVE-2019-25087

A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file…

Fix: 2019-09-08+
Fix from $1,950 2022-12-27
Flatpress CRITICAL 9.8
CVE-2022-4748

A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanag…

Patch available
Fix from $2,300 2022-12-27
Myvue MEDIUM 6.5
CVE-2021-39369

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access fil…

Fix: after 12.2.1.5
Fix from $1,600 2022-12-26
Android Processing Development Environment CRITICAL 9.8
CVE-2020-36628

A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/cal…

Fix: 0.5.2+
Fix from $2,300 2022-12-25
Httpster HIGH 7.5
CVE-2020-36629

A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.c…

Fix: 2020-11-19+
Fix from $1,950 2022-12-25
Planet Estream MEDIUM 6.5
CVE-2022-45894

GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.

Fix: 6.72.10.07+
Fix from $1,600 2022-12-25
Lieferantenmanager HIGH 7.5
CVE-2022-44016

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call…

Fix: 5.6+
Fix from $1,950 2022-12-25
Intouch Access Anywhere HIGH 7.5
CVE-2022-23854EPSS 46%

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with net…

Fix: 2020+
Fix from $1,950 2022-12-23
Thinkphp CRITICAL 9.8
CVE-2022-47945EPSS 16%

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). …

Fix: 6.0.14+
Fix from $2,300 2022-12-23
Tauri HIGH 7.7
CVE-2022-46171

Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file pa…

Fix: 1.0.8 / 1.1.3+
Fix from $1,950 2022-12-23
Nbnbk MEDIUM 6.5
CVE-2022-46492

nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/get…

No fix yet
Fix from $1,600 2022-12-23
Iboot Pdu4 N20 Firmware CRITICAL 9.8
CVE-2022-3184EPSS 12%

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to a…

Fix: 1.42.06162022+
Fix from $2,300 2022-12-21
Fastmile Firmware MEDIUM 6.5
CVE-2022-36221

Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the …

No fix yet
Fix from $1,600 2022-12-21
Lite Dev Server HIGH 7.5
CVE-2022-25895

All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the r…

No fix yet
Fix from $1,950 2022-12-21
Emui HIGH 7.5
CVE-2021-46856

The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiali…

Mitigation only
Fix from $1,950 2022-12-20
Emui HIGH 7.5
CVE-2022-41591

The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.

Mitigation only
Fix from $1,950 2022-12-20
Easy Static Server HIGH 7.5
CVE-2022-25931

All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to th…

No fix yet
Fix from $1,950 2022-12-20
Spectrum Scale MEDIUM 6.8
CVE-2022-40607

IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directorie…

Fix: after 5.1.4.0
Fix from $1,600 2022-12-19
Blogengine.net HIGH 7.2
CVE-2022-41418

An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary …

Patch available
Fix from $1,950 2022-12-19
Inpost Gallery CRITICAL 9.8
CVE-2022-4063EPSS 10%

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force th…

Fix: 2.1.4.1+
Fix from $2,300 2022-12-19
Tjws2 CRITICAL 9.8
CVE-2022-4594

A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the function deployWar of the file …

Fix: 2022-05-24+
Fix from $2,300 2022-12-18
Jlems HIGH 8.8
CVE-2022-4583

A vulnerability was found in jLEMS. It has been declared as critical. Affected by this vulnerability is the function unpackJar of the file src/main/j…

Fix: 2022-07-29+
Fix from $1,950 2022-12-17
Ubi Reader HIGH 7.1
CVE-2022-4572

A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue is the function ubireader_extr…

Fix: after 0.8.0
Fix from $1,950 2022-12-17
Guarddog HIGH 7.8
CVE-2022-23531

GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to 0.1.5 are vulnerable to Relative Path Traversal when scanning a special…

Fix: 0.1.5+
Fix from $1,950 2022-12-17
Guarddog MEDIUM 6.5
CVE-2022-23530

GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file write when scanning a specially…

Fix: 0.1.8+
Fix from $1,600 2022-12-16
Aerocms HIGH 7.5
CVE-2022-46137

AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.

No fix yet
Fix from $1,950 2022-12-16
Android MEDIUM 6.7
CVE-2022-20505

In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv…

Patch available
Fix from $1,600 2022-12-16
Alist CRITICAL 9.8
CVE-2022-45969

Alist v3.4.0 is vulnerable to Directory Traversal,

Patch available
Fix from $2,300 2022-12-15