Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Digital Experience Platform HIGH 7.5
CVE-2022-42125

Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers t…

Fix: 7.4.3.36+
Fix from $1,950 2022-11-15
Confluence Data Center HIGH 7.5
CVE-2022-42977

The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export i…

Fix: 1.3.5+
Fix from $1,950 2022-11-15
Powershell Universal HIGH 7.2
CVE-2022-45184

The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which al…

Fix: 3.4.7 / 3.5.3+
Fix from $1,950 2022-11-14
Libiec61850 HIGH 8.8
CVE-2022-3976

A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file…

Fix: 1.5+
Fix from $1,950 2022-11-13
Ultimate Member HIGH 7.5
CVE-2022-3966

A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_templat…

Fix: 2.5.1+
Fix from $1,950 2022-11-13
Nuc Kit Wireless Adapter Driver Installer HIGH 7.8
CVE-2022-36400

Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenti…

Fix: 22.40.0+
Fix from $1,950 2022-11-11
Ferry CRITICAL 9.8
CVE-2022-3940

A vulnerability, which was classified as problematic, was found in lanyulei ferry. This affects an unknown part of the file apis/process/task.go. The…

Mitigation only
Fix from $2,300 2022-11-11
Ferry CRITICAL 9.8
CVE-2022-3939

A vulnerability, which was classified as critical, has been found in lanyulei ferry. Affected by this issue is some unknown functionality of the file…

Mitigation only
Fix from $2,300 2022-11-11
Remote Access Server Firmware HIGH 7.5
CVE-2022-41607

All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory travers…

Fix: after 4.5.0
Fix from $1,950 2022-11-10
Agentflow HIGH 7.5
CVE-2022-39037

Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass …

Mitigation only
Fix from $1,950 2022-11-10
Upsmon Pro MEDIUM 6.5
CVE-2022-38120EPSS 6%

UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authenticatio…

Mitigation only
Fix from $1,600 2022-11-10
Expresscluster X CRITICAL 9.8
CVE-2022-34822

Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServer…

Fix: after 5.0
Fix from $2,300 2022-11-08
Android MEDIUM 5.5
CVE-2022-20453

In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local deni…

Mitigation only
Fix from $1,600 2022-11-08
Ivy HIGH 7.5
CVE-2022-37866

When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include pla…

Fix: 2.5.1+
Fix from $1,950 2022-11-07
Ivy CRITICAL 9.1
CVE-2022-37865

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip…

Fix: 2.5.1+
Fix from $2,300 2022-11-07
Wp All Import HIGH 7.2
CVE-2022-2711

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing hig…

Fix: 3.6.9+
Fix from $1,950 2022-11-07
Moni\ HIGH 7.5
CVE-2020-12509

In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the camera-file modul…

Fix: 4.2+
Fix from $1,950 2022-11-07
Identity Services Engine HIGH 8.8
CVE-2022-20962

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make una…

Mitigation only
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41670

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41667

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user…

Fix: 3.3+
Fix from $1,950 2022-11-04
Openharmony MEDIUM 6.5
CVE-2022-43451

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arb…

Fix: after 3.1.2
Fix from $1,600 2022-11-03
Uimaj HIGH 7.5
CVE-2022-32287

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files o…

Fix: after 3.3.0
Fix from $1,950 2022-11-03
Vantara Pentaho MEDIUM 6.5
CVE-2021-45448

Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates w…

Fix: 8.3.0.25 / 9.2.0.2+
Fix from $1,600 2022-11-02
Ipados MEDIUM 5.3
CVE-2022-32938

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 16.1 and iPadOS 16, macOS …

Fix: 13.0 / 16.0+
Fix from $1,600 2022-11-01
Dolphinscheduler MEDIUM 6.5
CVE-2022-34662

When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade…

Fix: 3.0.0+
Fix from $1,600 2022-11-01
Infrasuite Device Master CRITICAL 9.8
CVE-2022-41657EPSS 21%

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-41772EPSS 25%

Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Ind780 Firmware HIGH 7.5
CVE-2021-40661

A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing Terminals Build…

No fix yet
Fix from $1,950 2022-10-31
U Office Force MEDIUM 6.5
CVE-2022-39022

U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to …

Fix: after 20.50.7821d
Fix from $1,600 2022-10-31
U Office Force MEDIUM 6.5
CVE-2022-39023

U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to …

Fix: after 20.50.7821d
Fix from $1,600 2022-10-31