Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Galaxy HIGH 7.5
CVE-2022-23470

Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, wh…

Fix: after 22.05
Fix from $1,950 2022-12-06
Dialink HIGH 7.5
CVE-2022-2969

Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d…

Fix: 1.5.0.0+
Fix from $1,950 2022-12-01
My Cloud Home Firmware HIGH 7.8
CVE-2022-29837

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to ini…

Fix: 8.12.0-178+
Fix from $1,950 2022-12-01
Simple\ HIGH 8.1
CVE-2022-4030

The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be man…

Fix: after 6.8.0
Fix from $1,950 2022-11-29
Static Dev Server HIGH 7.5
CVE-2022-25848

This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the pa…

No fix yet
Fix from $1,950 2022-11-29
Fineract HIGH 8.8
CVE-2022-44635EPSS 69%

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Ap…

Fix: 1.8.1+
Fix from $1,950 2022-11-29
Fusionauth HIGH 7.5
CVE-2022-45921

FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker m…

Fix: 1.41.3+
Fix from $1,950 2022-11-28
Eyoom Builder CRITICAL 9.8
CVE-2022-41158

Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploi…

Fix: after 4.5.3
Fix from $2,300 2022-11-25
Frappe MEDIUM 6.5
CVE-2022-41712

Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc…

No fix yet
Fix from $1,600 2022-11-25
Pasvisu HIGH 7.5
CVE-2022-40977

A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious …

Fix: 1.6.102 / 1.12.0+
Fix from $1,950 2022-11-24
Pas 4000 MEDIUM 5.5
CVE-2022-40976

A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuratio…

Fix: 1.4.0 / 1.4.1+
Fix from $1,600 2022-11-24
Knime Analytics Platform HIGH 7.0
CVE-2022-44749

A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files …

Fix: 4.6.4+
Fix from $1,950 2022-11-24
Knime Server HIGH 7.5
CVE-2022-44748

A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritte…

Fix: 4.13.6 / 4.14.3+
Fix from $1,950 2022-11-24
Fedora MEDIUM 5.3
CVE-2022-45866

qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../…

Fix: 11.3+
Fix from $1,600 2022-11-23
Automotive Shop Management System MEDIUM 6.5
CVE-2022-44280

Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.

No fix yet
Fix from $1,600 2022-11-23
Testng HIGH 7.8
CVE-2022-4065

A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function …

Patch available
Fix from $1,950 2022-11-19
Welcart E Commerce CRITICAL 9.8
CVE-2022-41840EPSS 5%

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

Fix: 2.7.8+
Fix from $2,300 2022-11-18
F Secure Policy Manager CRITICAL 9.8
CVE-2022-38165

Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary loca…

Mitigation only
Fix from $2,300 2022-11-17
Webvendome MEDIUM 5.3
CVE-2022-39178

Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. Internal Server IP and Full pat…

Mitigation only
Fix from $1,600 2022-11-17
Crimson MEDIUM 5.3
CVE-2022-3090

Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are …

Fix: 3.0+
Fix from $1,600 2022-11-17
Lancet HIGH 8.8
CVE-2022-41920

Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package…

Fix: 1.3.4 / 2.1.10+
Fix from $1,950 2022-11-17
Syngo Dynamics Cardiovascular Imaging And Information System MEDIUM 5.3
CVE-2022-42892

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an ope…

Mitigation only
Fix from $1,600 2022-11-17
Backclick CRITICAL 9.8
CVE-2022-44006

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, un…

No fix yet
Fix from $2,300 2022-11-16
Backclick MEDIUM 6.5
CVE-2022-44008

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-en…

No fix yet
Fix from $1,600 2022-11-16
Fedora MEDIUM 5.7
CVE-2022-39347

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for…

Fix: 2.9.0+
Fix from $1,600 2022-11-16
Guitar Pro HIGH 7.5
CVE-2022-43264

Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted…

Fix: 1.10.2+
Fix from $1,950 2022-11-16
Moni\ HIGH 7.5
CVE-2020-12508

In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the image-relocator m…

Fix: 4.2+
Fix from $1,950 2022-11-15
Config Rotator HIGH 7.5
CVE-2022-45388

Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers…

Fix: after 2.0.1
Fix from $1,950 2022-11-15
Pipeline Utility Steps HIGH 8.1
CVE-2022-45381

Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Com…

Fix: 2.13.2+
Fix from $1,950 2022-11-15
Digital Experience Platform HIGH 7.5
CVE-2022-42123

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before…

Fix: 7.4.3.19+
Fix from $1,950 2022-11-15