Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Rmc 100 Firmware CRITICAL 9.8
CVE-2022-0902EPSS 17%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma…

Fix: 2105298-024 / 2105457-037+
Fix from $2,300 2022-07-21
Genesis64 HIGH 7.5
CVE-2022-29834

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97…

Mitigation only
Fix from $1,950 2022-07-20
Ignition HIGH 8.8
CVE-2022-1264

The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.

Fix: 8.1.10+
Fix from $1,950 2022-07-20
Goldshell Miner Firmware HIGH 7.5
CVE-2022-24659

Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve ar…

Fix: after 2.2.1
Fix from $1,950 2022-07-20
Fortiap U MEDIUM 6.7
CVE-2022-30301

A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to del…

Fix: after 6.2.3
Fix from $1,600 2022-07-19
Fortideceptor HIGH 8.1
CVE-2022-30302

Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 throu…

Fix: after 3.3.2
Fix from $1,950 2022-07-19
Usg Flex 100w Firmware MEDIUM 6.5
CVE-2022-2030

A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of …

Fix: after 5.30
Fix from $1,600 2022-07-19
Forticlient HIGH 7.8
CVE-2021-41031

A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a…

Fix: after 7.0.2
Fix from $1,950 2022-07-18
Softguard Web MEDIUM 6.5
CVE-2022-31202

The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.

Fix: 5.1.5+
Fix from $1,600 2022-07-17
Pyenv HIGH 7.8
CVE-2022-35861

pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a…

Fix: after 2.3.2
Fix from $1,950 2022-07-17
Aws Sdk Java MEDIUM 6.5
CVE-2022-31159

The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` m…

Fix: after 1.12.260
Fix from $1,600 2022-07-15
I3geo CRITICAL 9.8
CVE-2022-32409EPSS 13%

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to …

No fix yet
Fix from $2,300 2022-07-14
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34762

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware …

Fix: after 1.10
Fix from $1,950 2022-07-13
Android HIGH 7.8
CVE-2022-20220

In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv…

Patch available
Fix from $1,950 2022-07-13
Shackerpanel CRITICAL 9.3
CVE-2022-31576

The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used …

Fix: after 2021-05-25
Fix from $2,300 2022-07-11
Audio Aligner App CRITICAL 9.3
CVE-2022-31577

The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is us…

Fix: after 2020-01-10
Fix from $2,300 2022-07-11
Bt Lnmp HIGH 7.5
CVE-2022-31578

The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2019-10-10
Fix from $1,950 2022-07-11
Iasset CRITICAL 9.3
CVE-2022-31579

The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2022-05-04
Fix from $2,300 2022-07-11
Caretakerr Api CRITICAL 9.3
CVE-2022-31580

The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used …

Fix: after 2021-05-17
Fix from $2,300 2022-07-11
Openmf CRITICAL 9.3
CVE-2022-31581

The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: 2022-05-03+
Fix from $2,300 2022-07-11
Videoserver CRITICAL 9.3
CVE-2022-31582

The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2019-09-21
Fix from $2,300 2022-07-11
Automatedquizeval CRITICAL 9.3
CVE-2022-31583

The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function i…

Fix: after 2020-04-27
Fix from $2,300 2022-07-11
S3label CRITICAL 9.3
CVE-2022-31584

The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2019-08-14
Fix from $2,300 2022-07-11
Home Internet CRITICAL 9.3
CVE-2022-31585

The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used…

Fix: after 2020-08-28
Fix from $2,300 2022-07-11
Changepop Back CRITICAL 9.3
CVE-2022-31586

The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function i…

Fix: after 2019-06-04
Fix from $2,300 2022-07-11
Kg Fashion Chatbot CRITICAL 9.3
CVE-2022-31587

The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is use…

Fix: after 2018-05-22
Fix from $2,300 2022-07-11
Testplatform CRITICAL 9.3
CVE-2022-31588

The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2016-07-19
Fix from $2,300 2022-07-11
Python Athena Stack CRITICAL 9.3
CVE-2022-31550

The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafel…

Fix: after 2019-11-08
Fix from $2,300 2022-07-11
Flask Mongo Skel CRITICAL 9.3
CVE-2022-31551

The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used un…

Fix: after 2012-11-01
Fix from $2,300 2022-07-11
Anuvaad Corpus CRITICAL 9.3
CVE-2022-31552

The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is use…

Fix: after 2020-11-23
Fix from $2,300 2022-07-11