Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Fan Platform CRITICAL 9.3
CVE-2022-31514

The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used uns…

Fix: after 2021-04-20
Fix from $2,300 2022-07-11
Carceresbe CRITICAL 9.3
CVE-2022-31515

The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

No fix yet
Fix from $2,300 2022-07-11
Harveyzyh Python CRITICAL 9.3
CVE-2022-31516

The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2022-05-04
Fix from $2,300 2022-07-11
Mercury Sample Manager CRITICAL 9.3
CVE-2022-31517

The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2021-04-20
Fix from $2,300 2022-07-11
Python Recipe Database CRITICAL 9.3
CVE-2022-31518

The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send…

Fix: after 2021-03-31
Fix from $2,300 2022-07-11
Windmill CRITICAL 9.3
CVE-2022-31519

The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

No fix yet
Fix from $2,300 2022-07-11
Logstash Management Api CRITICAL 9.3
CVE-2022-31520

The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is us…

Fix: after 2020-05-04
Fix from $2,300 2022-07-11
Mosaic CRITICAL 9.3
CVE-2022-31521

The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

No fix yet
Fix from $2,300 2022-07-11
Karaokey CRITICAL 9.3
CVE-2022-31522

The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2019-12-11
Fix from $2,300 2022-07-11
Anakin CRITICAL 9.3
CVE-2022-31523

The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 0.1.1
Fix from $2,300 2022-07-11
Pure Swagger CRITICAL 9.3
CVE-2022-31524

The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used un…

Fix: after 1.1.5
Fix from $2,300 2022-07-11
Debian Linux HIGH 7.5
CVE-2022-35410

mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect…

Fix: 0.13.0+
Fix from $1,950 2022-07-08
Webpanel CRITICAL 9.8
CVE-2022-25046EPSS 56%

A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

Fix: after 0.9.8.1124
Fix from $2,300 2022-07-07
Unified Communications Manager MEDIUM 6.5
CVE-2022-20791

A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Ma…

Fix: 14su2+
Fix from $1,600 2022-07-06
Expressway MEDIUM 6.5
CVE-2022-20812

Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication S…

Mitigation only
Fix from $1,600 2022-07-06
Beego CRITICAL 9.8
CVE-2022-31836

The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

Fix: after 2.0.3
Fix from $2,300 2022-07-05
Manageengine Servicedesk Plus Msp HIGH 7.5
CVE-2022-32551

Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).

Fix: 10.6+
Fix from $1,950 2022-07-02
R1510 Firmware CRITICAL 9.1
CVE-2022-28127EPSS 35%

A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request …

No fix yet
Fix from $2,300 2022-06-30
Simplessus HIGH 8.1
CVE-2017-20105

A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the arg…

No fix yet
Fix from $1,950 2022-06-28
Openeclass MEDIUM 6.5
CVE-2022-33116

An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to re…

Fix: after 3.12.4
Fix from $1,600 2022-06-27
Album Lock MEDIUM 5.5
CVE-2017-20102

A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. T…

Mitigation only
Fix from $1,600 2022-06-27
Product Configurator For Woocommerce CRITICAL 9.1
CVE-2022-1953

The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, acc…

Fix: 1.2.32+
Fix from $2,300 2022-06-27
Dcmtk CRITICAL 9.8
CVE-2022-2119

OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files i…

Fix: 3.6.7+
Fix from $2,300 2022-06-24
Dcmtk CRITICAL 9.8
CVE-2022-2120

OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM fi…

Fix: 3.6.7+
Fix from $2,300 2022-06-24
Concrete Cms CRITICAL 9.1
CVE-2022-30117

Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrar…

Fix: 8.5.8 / 9.1.0+
Fix from $2,300 2022-06-24
Local Run Manager CRITICAL 9.8
CVE-2022-1518

LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure.

Fix: after 3.1
Fix from $2,300 2022-06-24
Opencart MEDIUM 6.5
CVE-2013-1891EPSS 6%

In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.

Fix: after 1.5.5.1
Fix from $1,600 2022-06-24
Ftp Server MEDIUM 6.5
CVE-2021-41636

MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating…

No fix yet
Fix from $1,600 2022-06-24
Pipeline\ HIGH 7.5
CVE-2022-34177

Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the …

Fix: after 448.v37cea_9a_10a_70
Fix from $1,950 2022-06-23
Embeddable Build Status HIGH 7.5
CVE-2022-34179

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image sty…

Fix: after 2.0.3
Fix from $1,950 2022-06-23