Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Container Storage Modules MEDIUM 6.5
CVE-2022-34375

Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user wi…

Fix: 1.3.0+
Fix from $1,600 2022-08-30
Hc Ip9100hd Firmware HIGH 7.5
CVE-2022-37681

Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traver…

Fix: after 1.07
Fix from $1,950 2022-08-29
Wpide HIGH 7.2
CVE-2022-2261

The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashb…

Fix: 3.0+
Fix from $1,950 2022-08-29
Ingredient Stock Management System MEDIUM 6.5
CVE-2022-36687

Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=d…

No fix yet
Fix from $1,600 2022-08-29
Zaver HIGH 7.5
CVE-2022-38794

Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.

Fix: after 2020-12-15
Fix from $1,950 2022-08-27
Htmly HIGH 8.1
CVE-2021-40285

htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

Patch available
Fix from $1,950 2022-08-26
Isagraf Workbench HIGH 7.8
CVE-2022-2463

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exc…

Fix: after 6.6.9
Fix from $1,950 2022-08-25
Isagraf Workbench HIGH 7.8
CVE-2022-2464

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can…

Fix: after 6.6.9
Fix from $1,950 2022-08-25
Windows Client HIGH 8.8
CVE-2022-32427

PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the drive…

Fix: 25.0.0.688+
Fix from $1,950 2022-08-25
Zenon HIGH 8.2
CVE-2022-34836

Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages an…

Fix: after 8.20
Fix from $1,950 2022-08-24
Taocms CRITICAL 9.1
CVE-2022-36261

An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?act…

No fix yet
Fix from $2,300 2022-08-23
Pukiwiki HIGH 7.2
CVE-2022-34486

Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a…

Fix: 1.5.4+
Fix from $1,950 2022-08-23
Avideo CRITICAL 9.9
CVE-2022-30547EPSS 64%

A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafte…

No fix yet
Fix from $2,300 2022-08-22
Team Wordpress Team Members Showcase HIGH 8.8
CVE-2022-2557

The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a pa…

Fix: 4.1.2+
Fix from $1,950 2022-08-22
Electric\'s Proficy HIGH 7.3
CVE-2022-2788

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip att…

Fix: after 9.80
Fix from $1,950 2022-08-19
Payara HIGH 7.5
CVE-2022-37422

Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

Fix: 4.1.2.191.36 / 5.42.0+
Fix from $1,950 2022-08-18
Flir Ax8 Firmware HIGH 7.5
CVE-2022-37060EPSS 18%

FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An un…

Fix: after 1.46.16
Fix from $1,950 2022-08-18
Edgeaggregator HIGH 7.2
CVE-2022-1373EPSS 13%

The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing z…

Mitigation only
Fix from $1,950 2022-08-17
E Flow HIGH 7.5
CVE-2021-42052

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query…

No fix yet
Fix from $1,950 2022-08-16
Commerce HIGH 8.8
CVE-2022-34254

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname t…

Fix: 2.3.7 / 2.4.3+
Fix from $1,950 2022-08-16
Debian Linux HIGH 7.5
CVE-2020-21365

Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a …

Fix: after 0.12.5
Fix from $1,950 2022-08-15
Manageengine Analytics Plus CRITICAL 9.8
CVE-2020-21642EPSS 7%

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke…

Mitigation only
Fix from $2,300 2022-08-15
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2022-37042 KEVEPSS 92%

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing aut…

Patch available
Fix from $2,300 2022-08-12
Awesome Procedures On Cypher HIGH 7.5
CVE-2022-37423

Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.

Fix: 4.3.0.7 / 4.4.0.8+
Fix from $1,950 2022-08-12
Sensor Management Server CRITICAL 9.8
CVE-2022-38129EPSS 19%

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management…

No fix yet
Fix from $2,300 2022-08-10
Go HIGH 7.5
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows po…

Fix: 1.17.11 / 1.18.3+
Fix from $1,950 2022-08-10
Wyse Management Suite MEDIUM 6.5
CVE-2022-34365

WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read ac…

Fix: 3.8.0+
Fix from $1,600 2022-08-10
Unified Communications Manager HIGH 8.1
CVE-2022-20816

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager S…

Fix: 14su2+
Fix from $1,950 2022-08-10
Notes MEDIUM 5.5
CVE-2022-36831

Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permiss…

Fix: 4.3.14.39+
Fix from $1,600 2022-08-05
Android MEDIUM 5.5
CVE-2022-33715

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of …

Mitigation only
Fix from $1,600 2022-08-05