Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Melis Asset Manager HIGH 7.5
CVE-2022-39296

MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affec…

Fix: 5.0.1+
Fix from $1,950 2022-10-11
Hybrid Client HIGH 7.5
CVE-2022-34430

Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability…

Fix: 1.8+
Fix from $1,950 2022-10-11
Container Storage Modules HIGH 8.8
CVE-2022-34426

Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which cou…

Fix: 2.0.0+
Fix from $1,950 2022-10-11
Factorycamera HIGH 7.8
CVE-2022-39858

Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamer…

Fix: 3.5.51+
Fix from $1,950 2022-10-07
Rdiffweb HIGH 7.5
CVE-2022-3389

Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

Fix: 2.4.10+
Fix from $1,950 2022-10-06
Netbackup HIGH 7.1
CVE-2022-42308

An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by le…

Fix: after 8.2
Fix from $1,950 2022-10-03
Netbackup HIGH 7.5
CVE-2022-42305

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path trav…

Fix: after 10.0.0.1
Fix from $1,950 2022-10-03
Mojoportal MEDIUM 6.5
CVE-2022-40123

mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability all…

No fix yet
Fix from $1,600 2022-10-03
Hybrid Client HIGH 7.1
CVE-2022-34429

Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability…

Mitigation only
Fix from $1,950 2022-09-30
Sd Wan Vbond Orchestrator HIGH 7.1
CVE-2022-20850

A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to dele…

Fix: 16.10.1 / 18.4.5+
Fix from $1,950 2022-09-30
Catalyst Sd Wan Manager HIGH 7.8
CVE-2022-20775 KEVEPSS 12%

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability i…

Fix: 20.6.3 / 20.7.2+
Fix from $1,950 2022-09-30
Sd Wan Vbond Orchestrator HIGH 7.8
CVE-2022-20818

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerab…

Fix: 20.9+
Fix from $1,950 2022-09-30
Htmly HIGH 8.1
CVE-2021-33354

Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter.

Fix: 2.8.1+
Fix from $1,950 2022-09-30
Cpy Car Park Server CRITICAL 9.8
CVE-2022-28814

Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulne…

Fix: 2.8.3 / 8.5.0.3+
Fix from $2,300 2022-09-28
Twig HIGH 7.5
CVE-2022-39261

Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem…

Fix: 1.44.7 / 2.15.3+
Fix from $1,950 2022-09-28
Hertz HIGH 7.5
CVE-2022-40082

Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.

Patch available
Fix from $1,950 2022-09-28
Smart Evision CRITICAL 9.8
CVE-2022-39033

Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL paramete…

Mitigation only
Fix from $2,300 2022-09-28
Smart Evision MEDIUM 6.5
CVE-2022-39034

Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote at…

Mitigation only
Fix from $1,600 2022-09-28
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2022-41352 KEVEPSS 95%

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extr…

Patch available
Fix from $2,300 2022-09-26
Icecoder HIGH 7.5
CVE-2022-34026

ICEcoder v8.1 allows attackers to execute a directory traversal.

No fix yet
Fix from $1,950 2022-09-22
Zzcms MEDIUM 5.3
CVE-2022-40443

An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/sitein…

No fix yet
Fix from $1,600 2022-09-22
Zzcms MEDIUM 5.3
CVE-2022-40444

ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.

No fix yet
Fix from $1,600 2022-09-22
Liferay Portal HIGH 7.5
CVE-2022-28981

Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside…

Fix: after 7.4.2
Fix from $1,950 2022-09-22
Windows Defender For Endpoint MEDIUM 5.5
CVE-2022-29799EPSS 12%

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeSt…

Patch available
Fix from $1,600 2022-09-21
Build Publisher MEDIUM 5.7
CVE-2022-41231

Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenki…

Fix: after 1.22
Fix from $1,600 2022-09-21
Identity And Directory Management System HIGH 7.5
CVE-2022-2265

The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vuln…

Fix: 2.1.25+
Fix from $1,950 2022-09-21
Mcwebserver Minecraft Mod For Fabric And Quilt HIGH 7.5
CVE-2022-39221

McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric …

Fix: after 0.1.2.1
Fix from $1,950 2022-09-21
Fme Server HIGH 7.2
CVE-2022-38340

Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.

Fix: 2021.2.6 / 2022.0.1+
Fix from $1,950 2022-09-20
Securegate CRITICAL 9.8
CVE-2022-23767

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfe…

Fix: after 3.5.5
Fix from $2,300 2022-09-19
Spectrum Protect Plus HIGH 7.5
CVE-2022-40608

IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating…

Fix: after 10.1.11
Fix from $1,950 2022-09-19