Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Docsys HIGH 7.5
CVE-2022-4511

A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the compo…

No fix yet
Fix from $1,950 2022-12-15
Easywebpack Cli MEDIUM 5.3
CVE-2020-24855

Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.

Fix: 4.5.2+
Fix from $1,600 2022-12-15
Lansweeper MEDIUM 6.5
CVE-2022-29511

A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A spe…

No fix yet
Fix from $1,600 2022-12-15
Lansweeper HIGH 8.8
CVE-2022-29517EPSS 58%

A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-craf…

No fix yet
Fix from $1,950 2022-12-15
Lansweeper HIGH 8.8
CVE-2022-32573

A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP …

No fix yet
Fix from $1,950 2022-12-15
Lansweeper MEDIUM 6.5
CVE-2022-27498EPSS 38%

A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A…

Mitigation only
Fix from $1,600 2022-12-15
Vrealize Log Insight HIGH 7.5
CVE-2022-31703

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system…

Fix: after 8.10.1
Fix from $1,950 2022-12-14
Enterprise Server CRITICAL 9.8
CVE-2022-46255

An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code exec…

Mitigation only
Fix from $2,300 2022-12-14
Enterprise Server HIGH 8.8
CVE-2022-46256

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To ex…

Fix: 3.3.17 / 3.4.12+
Fix from $1,950 2022-12-14
Metersphere HIGH 8.1
CVE-2022-23512

MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::de…

Fix: 2.4.1+
Fix from $1,950 2022-12-14
Scifio CRITICAL 9.8
CVE-2022-4493

A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUnpackResource of the file src/…

Fix: 2022-07-29+
Fix from $2,300 2022-12-14
Mcp Mapping Viewer CRITICAL 9.8
CVE-2022-4494

A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is the function extractZip of th…

Fix: 2022-09-22+
Fix from $2,300 2022-12-14
Atlas HIGH 8.8
CVE-2022-34271

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas ver…

Fix: after 2.2.0
Fix from $1,950 2022-12-14
Genesis64 HIGH 7.1
CVE-2022-40264

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versions 10.96 …

Fix: after 10.97.2
Fix from $1,950 2022-12-14
Google Search HIGH 7.8
CVE-2022-29580

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symb…

Fix: 13.41+
Fix from $1,950 2022-12-13
Linx Sphere HIGH 7.5
CVE-2022-45269

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

No fix yet
Fix from $1,950 2022-12-12
Edgeconnect Enterprise MEDIUM 6.5
CVE-2022-44532

An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vuln…

Fix: after 9.2.1.0
Fix from $1,600 2022-12-12
Apex One HIGH 7.8
CVE-2022-44653

A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privile…

Fix: 14.0.11789+
Fix from $1,950 2022-12-12
Edgeconnect Enterprise MEDIUM 6.5
CVE-2022-43518

An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability…

Fix: after 9.2.1.0
Fix from $1,600 2022-12-12
Sd Wan HIGH 8.1
CVE-2022-37906

An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in t…

Fix: 6.5.4.22 / 8.6.0.17+
Fix from $1,950 2022-12-12
Docsys HIGH 7.2
CVE-2022-4402

A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompressio…

Fix: after 2.02.37
Fix from $1,950 2022-12-11
Kbase Doc CRITICAL 9.1
CVE-2022-45290

Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.

No fix yet
Fix from $2,300 2022-12-09
Intellij Idea MEDIUM 5.5
CVE-2022-46826

In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.

Fix: 2022.3+
Fix from $1,600 2022-12-08
Go HIGH 7.5
CVE-2022-41720

On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files roo…

Fix: 1.18.9 / 1.19.4+
Fix from $1,950 2022-12-07
Echo MEDIUM 5.3
CVE-2020-36565

Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files out…

Fix: 4.2.0+
Fix from $1,600 2022-12-07
Casdoor HIGH 8.1
CVE-2022-44942

Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.

Fix: 1.126.1+
Fix from $1,950 2022-12-07
Easy Wp Smtp HIGH 8.1
CVE-2022-45829

Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.

Fix: after 1.5.1
Fix from $1,950 2022-12-06
Easy Wp Smtp MEDIUM 6.5
CVE-2022-45833

Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

Fix: after 1.5.1
Fix from $1,600 2022-12-06
Py7zr CRITICAL 9.1
CVE-2022-44900

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to wri…

Fix: 0.20.1+
Fix from $2,300 2022-12-06
Kodexplorer HIGH 7.5
CVE-2022-46154

Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users …

Fix: 4.50+
Fix from $1,950 2022-12-06