Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
1350 Optical Management System MEDIUM 6.5
CVE-2022-40713

An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter,…

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.5
CVE-2022-40715

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, al…

Mitigation only
Fix from $1,600 2022-09-19
Zentao HIGH 7.5
CVE-2022-37700

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https:/…

No fix yet
Fix from $1,950 2022-09-19
Nextcloud MEDIUM 5.5
CVE-2022-39210

Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not pr…

Fix: 3.21.0+
Fix from $1,600 2022-09-17
Emui HIGH 7.5
CVE-2022-39001

The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.

No fix yet
Fix from $1,950 2022-09-16
Pds Vista 7 MEDIUM 6.5
CVE-2022-34002

The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows…

Fix: 7.1.7.2+
Fix from $1,600 2022-09-16
Tauri MEDIUM 5.8
CVE-2022-39215

Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it …

Fix: 1.0.6+
Fix from $1,600 2022-09-15
Kubevirt MEDIUM 6.5
CVE-2022-1798

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arb…

Fix: 0.55.1+
Fix from $1,600 2022-09-15
Laravel Filemanager MEDIUM 6.5
CVE-2022-40734

UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as…

Fix: after 2.5.1
Fix from $1,600 2022-09-14
Onedev HIGH 8.8
CVE-2022-38301

Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR …

Patch available
Fix from $1,950 2022-09-14
Cargo HIGH 8.1
CVE-2022-36113

Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on…

Fix: 0.65.0+
Fix from $1,950 2022-09-14
Android HIGH 7.8
CVE-2022-20395

In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privile…

Mitigation only
Fix from $1,950 2022-09-13
Go HIGH 7.5
CVE-2022-32190

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the U…

Patch available
Fix from $1,950 2022-09-13
Goomph HIGH 8.8
CVE-2022-26049

This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destinatio…

Fix: 3.37.2+
Fix from $1,950 2022-09-11
Casdoor CRITICAL 9.1
CVE-2022-38638

Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.

Patch available
Fix from $2,300 2022-09-09
Smartvista Cardgen HIGH 7.5
CVE-2022-38614

An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifyi…

No fix yet
Fix from $1,950 2022-09-09
Smartvista Cardgen MEDIUM 6.5
CVE-2022-38613

A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.

No fix yet
Fix from $1,600 2022-09-09
A\+hrd HIGH 8.1
CVE-2022-28741

aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing inpu…

Fix: 5.4.1125v112 / 5.5.1098v156+
Fix from $1,950 2022-09-09
Shirne Cms MEDIUM 6.5
CVE-2022-37299

An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/co…

Patch available
Fix from $1,600 2022-09-09
Dir 819 Firmware HIGH 8.1
CVE-2022-38258

A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server inf…

No fix yet
Fix from $1,950 2022-09-08
Wikmd HIGH 7.5
CVE-2022-36081

Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when accessing `/list/<path:folderpath>`…

Fix: 1.7.1+
Fix from $1,950 2022-09-07
Growthbook HIGH 7.5
CVE-2022-36065

GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, att…

Fix: 1.6.0+
Fix from $1,950 2022-09-06
Fortisoar MEDIUM 6.5
CVE-2022-29062

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underly…

Fix: 7.0.3+
Fix from $1,600 2022-09-06
Systematic Fix Adapter Firmware HIGH 8.6
CVE-2022-39838

Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to…

No fix yet
Fix from $1,950 2022-09-05
Emc Powerscale Onefs MEDIUM 5.5
CVE-2022-34378

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. …

Fix: after 9.4.0.3
Fix from $1,600 2022-09-02
Ofbiz CRITICAL 9.8
CVE-2022-25371

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Kkfileview MEDIUM 6.5
CVE-2022-36593

kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.

No fix yet
Fix from $1,600 2022-09-02
Command \| Integration Suite For System Center HIGH 7.8
CVE-2022-34373

Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated mal…

Fix: 6.2.0+
Fix from $1,950 2022-08-31
Pcoweb Card Firmware HIGH 7.5
CVE-2022-37122EPSS 19%

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticate…

No fix yet
Fix from $1,950 2022-08-31
Flux2 HIGH 7.8
CVE-2022-36035

Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration…

Fix: 0.32.0+
Fix from $1,950 2022-08-31