Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
GitLab MEDIUM 5.3
CVE-2022-2531

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all…

Fix: 15.0.5 / 15.1.4+
Fix from $1,600 2022-08-05
Identity Manager HIGH 7.5
CVE-2022-31662

VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with netw…

Patch available
Fix from $1,950 2022-08-05
Fabric Operating System MEDIUM 5.5
CVE-2021-27798

A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric O…

Mitigation only
Fix from $1,600 2022-08-05
Muhttpd HIGH 7.5
CVE-2022-31793EPSS 16%

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before …

Fix: 1.1.7+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.7
CVE-2022-31473

In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attacker may be able to bypass App…

Fix: 15.1.4+
Fix from $1,950 2022-08-04
Planka MEDIUM 6.5
CVE-2022-2653

With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environ…

Fix: 1.5.1+
Fix from $1,600 2022-08-04
Omicard Edm HIGH 7.5
CVE-2022-32963

OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pa…

Fix: after 6.0
Fix from $1,950 2022-08-04
Omicard Edm HIGH 7.5
CVE-2022-35216

OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-p…

Fix: after 6.0
Fix from $1,950 2022-08-04
Storage Analyzer MEDIUM 6.5
CVE-2022-27618

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before …

Fix: 2.0.1-0214 / 2.1.0-0390+
Fix from $1,600 2022-08-03
Iway Service Manager MEDIUM 6.5
CVE-2022-30572

The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vul…

Fix: 8.0.7+
Fix from $1,600 2022-08-02
Streamlit MEDIUM 6.5
CVE-2022-35918

Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable t…

Fix: 1.11.1+
Fix from $1,600 2022-08-01
Sanic HIGH 7.5
CVE-2022-35920

Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using e…

Fix: 20.12.7 / 21.12.2+
Fix from $1,950 2022-08-01
Dspace HIGH 7.2
CVE-2022-31194

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace…

Fix: 6.4+
Fix from $1,950 2022-08-01
Dspace HIGH 7.2
CVE-2022-31195

DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServic…

Fix: 6.4+
Fix from $1,950 2022-08-01
Captcha 4wp HIGH 8.8
CVE-2022-2184

The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abu…

Fix: 7.1.0+
Fix from $1,950 2022-08-01
Twinsoft CRITICAL 9.8
CVE-2021-22650

An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to cod…

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Audio Station HIGH 8.1
CVE-2022-27611

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5…

Fix: 6.5.4-3367+
Fix from $1,950 2022-07-28
Webdav Server HIGH 8.1
CVE-2022-22685

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4…

Fix: 2.4.0-0062+
Fix from $1,950 2022-07-28
Dns Server HIGH 8.1
CVE-2022-27615

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-502…

Fix: 2.2.2-5027+
Fix from $1,950 2022-07-28
Goanywhere Managed File Transfer MEDIUM 6.5
CVE-2021-46830

A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerabi…

Fix: 6.8.3+
Fix from $1,600 2022-07-27
Deployer Framework HIGH 8.8
CVE-2022-36889

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployme…

Fix: after 85.v1d1888e8c021
Fix from $1,950 2022-07-27
Sims MEDIUM 6.5
CVE-2022-34551

Sims v1.0 was discovered to allow path traversal when downloading attachments.

No fix yet
Fix from $1,600 2022-07-27
Diskstation Manager HIGH 8.1
CVE-2022-27610

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM…

Fix: 6.2.3-25423+
Fix from $1,950 2022-07-27
Pandora Fms HIGH 7.2
CVE-2022-1648

Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intend…

Fix: after 7.0_ng_760
Fix from $1,950 2022-07-26
Qr Code Generator HIGH 7.5
CVE-2022-24992

A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.

Fix: after 5.2.7
Fix from $1,950 2022-07-25
Moodle HIGH 7.5
CVE-2022-35650EPSS 49%

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in…

Fix: 3.9.15 / 3.11.8+
Fix from $1,950 2022-07-25
Responsive Filemanager CRITICAL 9.8
CVE-2017-20145

A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The att…

Fix: after 9.11.0
Fix from $2,300 2022-07-25
Chrome MEDIUM 6.5
CVE-2022-1128

Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to …

Fix: 100.0.4896.60+
Fix from $1,600 2022-07-23
Iview CRITICAL 9.8
CVE-2022-2139EPSS 15%

The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.

Fix: 5.7.04.6469+
Fix from $2,300 2022-07-22
Debian Linux HIGH 8.1
CVE-2022-31163

TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as …

Fix: 0.3.61 / 1.2.10+
Fix from $1,950 2022-07-22