Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Dpkg CRITICAL 9.8
CVE-2022-1664

Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa…

Fix: 1.18.26 / 1.19.8+
Fix from $2,300 2022-05-26
Ginadmin HIGH 7.5
CVE-2022-30427

In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.

Fix: after 2022-05-10
Fix from $1,950 2022-05-25
Go Getter HIGH 8.6
CVE-2022-30321

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i…

Fix: after 1.5.11
Fix from $1,950 2022-05-25
Webserver MEDIUM 5.3
CVE-2021-32964

The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary fil…

Fix: after 4.0.40.1014
Fix from $1,600 2022-05-24
Filegator HIGH 8.1
CVE-2022-1850

Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.

Fix: 7.8.0+
Fix from $1,950 2022-05-24
Gitblit HIGH 7.5
CVE-2022-31268EPSS 11%

A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathna…

No fix yet
Fix from $1,950 2022-05-21
Cnmaestro HIGH 7.5
CVE-2022-1359

The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside…

Mitigation only
Fix from $1,950 2022-05-17
Dir 825 Firmware MEDIUM 6.5
CVE-2022-29332

D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the r…

No fix yet
Fix from $1,600 2022-05-17
Cmseasy HIGH 8.8
CVE-2021-42643

cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website…

No fix yet
Fix from $1,950 2022-05-17
Amministrazione Aperta MEDIUM 6.5
CVE-2022-1560

The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Loc…

Fix: 3.8+
Fix from $1,600 2022-05-16
Drawio HIGH 7.5
CVE-2022-1721

Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application.

Fix: 18.0.5+
Fix from $1,950 2022-05-16
Openclinica CRITICAL 9.8
CVE-2022-24830

OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vul…

Fix: 3.13.1 / 3.16.2+
Fix from $2,300 2022-05-14
Mypro HIGH 7.5
CVE-2021-33005

mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.

Fix: 8.20.0+
Fix from $1,950 2022-05-13
Blogengine.net CRITICAL 9.1
CVE-2022-25591

BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web serv…

No fix yet
Fix from $2,300 2022-05-13
Sametime HIGH 7.6
CVE-2021-27771

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m…

Mitigation only
Fix from $1,950 2022-05-12
Sysaid CRITICAL 9.8
CVE-2022-23166

Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" …

Fix: 22.1.64 / 22.2.20+
Fix from $2,300 2022-05-12
Sv Cpt Mc310 Firmware HIGH 7.5
CVE-2022-29298EPSS 47%

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

No fix yet
Fix from $1,950 2022-05-12
Enterprise Manager CRITICAL 9.8
CVE-2022-29596

MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../.…

No fix yet
Fix from $2,300 2022-05-11
Shopwind MEDIUM 5.3
CVE-2022-30058

Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.ph…

Fix: after 3.4.2
Fix from $1,600 2022-05-11
Shopwind MEDIUM 6.5
CVE-2022-30059

Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php.

Fix: after 3.4.2
Fix from $1,600 2022-05-11
Ftcms MEDIUM 6.5
CVE-2022-30061

ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp.

Fix: after 2.1
Fix from $1,600 2022-05-11
Ftcms MEDIUM 6.5
CVE-2022-30062

ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php

Fix: after 2.1
Fix from $1,600 2022-05-11
All In One Wp Migration MEDIUM 6.5
CVE-2022-1476EPSS 47%

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation…

Fix: after 7.58
Fix from $1,600 2022-05-10
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Splunk HIGH 8.8
CVE-2022-26889

In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an …

Fix: 8.1.2+
Fix from $1,950 2022-05-06
Flux2 MEDIUM 6.5
CVE-2022-24878

Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization…

Fix: 0.24.0 / 0.29.0+
Fix from $1,600 2022-05-06
Flux2 HIGH 8.8
CVE-2022-24877

Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization…

Fix: 0.24.0 / 0.29.0+
Fix from $1,950 2022-05-06
Qts MEDIUM 5.3
CVE-2021-38693

A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulne…

Fix: 4.5.4.1991 / 5.0.0.1986+
Fix from $1,600 2022-05-05
Masacms HIGH 7.5
CVE-2021-42183

MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

No fix yet
Fix from $1,950 2022-05-05
Android MEDIUM 5.5
CVE-2022-20101

In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional…

Mitigation only
Fix from $1,600 2022-05-03