Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
8373 Ip Zone Paging Adapter Firmware HIGH 8.8
CVE-2022-31395

Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent …

No fix yet
Fix from $1,950 2022-06-23
Remote Desktop Manager HIGH 7.5
CVE-2022-33995

A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an a…

Fix: 2022.2+
Fix from $1,950 2022-06-21
Ispy CRITICAL 9.8
CVE-2022-29774EPSS 6%

iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.

No fix yet
Fix from $2,300 2022-06-21
Glpi Inventory MEDIUM 5.3
CVE-2022-31062EPSS 6%

### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.…

Fix: 1.0.2+
Fix from $1,600 2022-06-20
Argo Events HIGH 7.5
CVE-2022-25856

The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read()…

Fix: 1.7.1+
Fix from $1,950 2022-06-17
Mathtype HIGH 7.5
CVE-2022-31372

Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a …

Patch available
Fix from $1,950 2022-06-16
Hadoop HIGH 8.8
CVE-2021-33036

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…

Fix: 2.10.2 / 3.2.3+
Fix from $1,950 2022-06-15
Fast Food Ordering System CRITICAL 9.1
CVE-2022-32328

Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.

No fix yet
Fix from $2,300 2022-06-14
T\&d Server HIGH 7.5
CVE-2022-29509

Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier,…

Fix: after 2.30
Fix from $1,950 2022-06-14
Jupiter HIGH 8.8
CVE-2022-1657

Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Pat…

Fix: after 6.10.1
Fix from $1,950 2022-06-13
Rccmd MEDIUM 6.5
CVE-2022-26041

Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter …

Fix: after 4.26
Fix from $1,600 2022-06-13
Supportassist For Business Pcs HIGH 7.1
CVE-2022-29093

Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) …

Fix: after 3.10.4
Fix from $1,950 2022-06-10
Supportassist For Business Pcs HIGH 7.1
CVE-2022-29094

Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) …

Fix: after 3.10.4
Fix from $1,950 2022-06-10
Convert Svg CRITICAL 9.8
CVE-2022-24278

The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerabili…

Fix: 0.6.4+
Fix from $2,300 2022-06-10
Safenet Keysecure MEDIUM 6.5
CVE-2021-42811

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to rea…

Fix: after 8.12.4
Fix from $1,600 2022-06-10
Gogs CRITICAL 9.1
CVE-2022-1992

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

Fix: 0.12.9+
Fix from $2,300 2022-06-09
Gogs HIGH 8.1
CVE-2022-1993EPSS 52%

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

Fix: 0.12.9+
Fix from $1,950 2022-06-09
Http File Server HIGH 8.1
CVE-2021-40668

The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directo…

No fix yet
Fix from $1,950 2022-06-09
Django S3file CRITICAL 9.8
CVE-2022-24840

django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 …

Fix: 5.5.1+
Fix from $2,300 2022-06-09
User Meta User Profile Builder And User Management MEDIUM 6.5
CVE-2022-0779

The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low …

Fix: 2.4.4+
Fix from $1,600 2022-06-08
Seeddms MEDIUM 6.5
CVE-2022-28478

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sani…

Patch available
Fix from $1,600 2022-06-06
Grafana HIGH 7.5
CVE-2022-32275EPSS 9%

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd …

No fix yet
Fix from $1,950 2022-06-06
Lp1501 Firmware HIGH 8.8
CVE-2022-31483

An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the …

Fix: 1.271+
Fix from $1,950 2022-06-06
Realplayer CRITICAL 9.8
CVE-2022-32270

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code …

No fix yet
Fix from $2,300 2022-06-03
Regulatory Reporting System MEDIUM 6.5
CVE-2022-29597

Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to refe…

No fix yet
Fix from $1,600 2022-06-02
Elite Cms MEDIUM 6.5
CVE-2022-30804

elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.

No fix yet
Fix from $1,600 2022-06-02
Webcube CRITICAL 9.8
CVE-2022-28945

An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.

Mitigation only
Fix from $2,300 2022-06-02
N6854a Firmware HIGH 7.5
CVE-2022-1661EPSS 16%

The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.

Fix: 2.4.0+
Fix from $1,950 2022-06-02
Curekit HIGH 7.5
CVE-2022-23082

In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which ma…

Fix: after 1.1.3
Fix from $1,950 2022-05-31
Dedecms MEDIUM 6.5
CVE-2022-30508

DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.

No fix yet
Fix from $1,600 2022-05-26