Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Mail Sqr Expert MEDIUM 6.5
CVE-2022-40742

Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitra…

Mitigation only
Fix from $1,600 2022-10-31
Qtiworks MEDIUM 6.5
CVE-2022-39367

QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine allows users to upload QTI con…

Fix: 1.0+
Fix from $1,600 2022-10-28
Dolphinscheduler MEDIUM 6.5
CVE-2022-26884

Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

Fix: 2.0.6+
Fix from $1,600 2022-10-28
C200 Firmware HIGH 7.5
CVE-2021-38399

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauth…

Mitigation only
Fix from $1,950 2022-10-28
R Seenet MEDIUM 5.3
CVE-2022-3387EPSS 14%

Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP…

Fix: after 2.4.19
Fix from $1,600 2022-10-27
Openlitespeed MEDIUM 5.8
CVE-2022-0072

Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This …

Fix: 1.7.16.1+
Fix from $1,600 2022-10-27
Telepresence Collaboration Endpoint HIGH 7.1
CVE-2022-20954

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.19.1+
Fix from $1,950 2022-10-26
Telepresence Collaboration Endpoint HIGH 7.1
CVE-2022-20955

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.19.1+
Fix from $1,950 2022-10-26
Telepresence Collaboration Endpoint MEDIUM 6.7
CVE-2022-20776

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.20.1+
Fix from $1,600 2022-10-26
Telepresence Collaboration Endpoint HIGH 7.2
CVE-2022-20811

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 9.15.13.0 / 10.15.1+
Fix from $1,950 2022-10-26
Identity Services Engine HIGH 8.1
CVE-2022-20822

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read a…

Mitigation only
Fix from $1,950 2022-10-26
Telepresence Collaboration Endpoint MEDIUM 5.5
CVE-2022-20953

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…

Fix: 10.19.1+
Fix from $1,600 2022-10-26
Presto File Server HIGH 7.5
CVE-2022-43748

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Ser…

Fix: 2.1.2-1601+
Fix from $1,950 2022-10-26
Gin Vue Admin HIGH 7.5
CVE-2022-39345

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5…

Fix: 2.5.4+
Fix from $1,950 2022-10-25
Arcgis Server HIGH 8.1
CVE-2022-38196

Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authent…

Fix: after 10.9.1
Fix from $1,950 2022-10-25
R1510 Firmware CRITICAL 9.1
CVE-2022-33897

A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted network reques…

No fix yet
Fix from $2,300 2022-10-25
F5os A MEDIUM 5.5
CVE-2022-41780

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the …

Fix: 1.1.0 / 1.4.0+
Fix from $1,600 2022-10-19
Lavalite HIGH 7.5
CVE-2022-42188

In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.

No fix yet
Fix from $1,950 2022-10-18
Rava Certificate Validation System HIGH 7.5
CVE-2022-39058

RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass …

Mitigation only
Fix from $1,950 2022-10-18
GitLab HIGH 7.3
CVE-2022-3060

Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to gene…

Fix: after 12.7.0
Fix from $1,950 2022-10-17
Tableau Server CRITICAL 9.8
CVE-2022-22128

Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow rem…

Fix: after 2022.1.4
Fix from $2,300 2022-10-17
Smart Wing Cms CRITICAL 9.8
CVE-2022-23770

This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remot…

Fix: 19051+
Fix from $2,300 2022-10-17
Coldfusion HIGH 7.2
CVE-2022-38421EPSS 79%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…

Patch available
Fix from $1,950 2022-10-14
Coldfusion HIGH 7.5
CVE-2022-38422EPSS 44%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…

Mitigation only
Fix from $1,950 2022-10-14
Coldfusion HIGH 7.2
CVE-2022-38424EPSS 45%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…

Mitigation only
Fix from $1,950 2022-10-14
Coldfusion CRITICAL 9.8
CVE-2022-38418EPSS 80%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…

Patch available
Fix from $2,300 2022-10-14
Access Controller HIGH 7.5
CVE-2021-22685

An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.

Fix: 2.0.1+
Fix from $1,950 2022-10-14
Global Management System HIGH 7.5
CVE-2021-20030

SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing applicat…

Fix: 9.3.2+
Fix from $1,950 2022-10-13
Geodrive HIGH 7.1
CVE-2022-33937

Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potential…

Fix: 2.2.3+
Fix from $1,950 2022-10-12
Manufacturing Execution HIGH 7.5
CVE-2022-39802EPSS 7%

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The …

No fix yet
Fix from $1,950 2022-10-11