Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Scout HIGH 7.5
CVE-2022-1554

Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.

Fix: 4.52+
Fix from $1,950 2022-05-03
Xwiki HIGH 7.5
CVE-2022-24897

APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.…

Fix: 12.6.7 / 12.10.3+
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.5
CVE-2022-29970

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

Fix: 2.2.0+
Fix from $1,950 2022-05-02
Nopcommerce HIGH 7.5
CVE-2022-28451

nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

Patch available
Fix from $1,950 2022-05-02
One Java Agent CRITICAL 9.8
CVE-2022-25842

All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a s…

Patch available
Fix from $2,300 2022-05-01
Pistache HIGH 7.5
CVE-2022-26068

This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.

Fix: 0.0.3.20220425+
Fix from $1,950 2022-05-01
Glewlwyd HIGH 7.5
CVE-2022-29967

static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.

Fix: after 2.6.2
Fix from $1,950 2022-04-29
Piano Led Visualizer HIGH 8.6
CVE-2022-24900EPSS 8%

Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vuln…

Fix: after 1.3
Fix from $1,950 2022-04-29
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-29081EPSS 84%

Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass …

No fix yet
Fix from $2,300 2022-04-28
Ts 550 Evo Firmware HIGH 7.5
CVE-2021-46420EPSS 6%

Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to …

No fix yet
Fix from $1,950 2022-04-27
Ts 550 Evo Firmware HIGH 7.5
CVE-2021-46421EPSS 6%

Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to ob…

No fix yet
Fix from $1,950 2022-04-27
Verydows HIGH 8.1
CVE-2022-28058

Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.

No fix yet
Fix from $1,950 2022-04-26
Verydows HIGH 8.1
CVE-2022-28059

Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.

No fix yet
Fix from $1,950 2022-04-26
Hongcms HIGH 8.1
CVE-2022-28523

HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

No fix yet
Fix from $1,950 2022-04-26
Dhcms HIGH 8.1
CVE-2022-28527

dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.

No fix yet
Fix from $1,950 2022-04-26
Xplatform HIGH 8.8
CVE-2021-26629

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompre…

Fix: 9.2.2.284+
Fix from $1,950 2022-04-26
Zoneminder CRITICAL 9.8
CVE-2022-29806EPSS 67%

ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contribut…

Fix: 1.36.13+
Fix from $2,300 2022-04-26
Serv U HIGH 7.5
CVE-2021-35250EPSS 13%

A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se…

Mitigation only
Fix from $1,950 2022-04-25
Active Iq Unified Manager CRITICAL 9.8
CVE-2022-23457

ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default imp…

Fix: 2.3.0.0+
Fix from $2,300 2022-04-25
Admin Word Count Column CRITICAL 9.8
CVE-2022-1390EPSS 22%

The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated …

Fix: after 2.2
Fix from $2,300 2022-04-25
Cab Fare Calculator CRITICAL 9.8
CVE-2022-1391EPSS 15%

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could l…

Fix: 1.0.4+
Fix from $2,300 2022-04-25
Videos Sync Pdf HIGH 7.5
CVE-2022-1392EPSS 11%

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Loc…

Fix: after 1.7.4
Fix from $1,950 2022-04-25
Web Proxy HIGH 8.1
CVE-2021-40680

There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via th…

Mitigation only
Fix from $1,950 2022-04-25
Emc Appsync HIGH 7.5
CVE-2022-24424

Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially…

Fix: 4.4.0.0+
Fix from $1,950 2022-04-21
Ucms HIGH 7.5
CVE-2022-28444

UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.

No fix yet
Fix from $1,950 2022-04-21
Unified Communications Manager MEDIUM 6.5
CVE-2022-20790

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager S…

Fix: after 14.0
Fix from $1,600 2022-04-21
Zimbra Collaboration Suite HIGH 7.2
CVE-2022-27925 KEVEPSS 99%

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated u…

Mitigation only
Fix from $1,950 2022-04-21
Roboguide MEDIUM 5.9
CVE-2021-43988

The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized acce…

Fix: after 9.40083.00.05
Fix from $1,600 2022-04-20
Simple File List HIGH 7.5
CVE-2022-1119EPSS 20%

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php fil…

Fix: 3.2.8+
Fix from $1,950 2022-04-19
Xenmobile Server HIGH 8.8
CVE-2021-44519

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

Mitigation only
Fix from $1,950 2022-04-19