Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Api Manager CRITICAL 9.8
CVE-2022-29464 KEVEPSS 100%

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Conten…

Fix: after 6.6.0
Fix from $2,300 2022-04-18
Notable HIGH 8.8
CVE-2022-29281

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the …

Fix: 1.9.0+
Fix from $1,950 2022-04-15
Ios Xe HIGH 7.2
CVE-2022-20718

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,950 2022-04-15
Ios Xe HIGH 7.2
CVE-2022-20719

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,950 2022-04-15
Ios Xe HIGH 7.2
CVE-2022-20720

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,950 2022-04-15
Ios Xe HIGH 7.2
CVE-2022-20723

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,950 2022-04-15
Cgr1000 Compute Module MEDIUM 5.3
CVE-2022-20724

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

No fix yet
Fix from $1,600 2022-04-15
Cgr1000 Compute Module HIGH 7.5
CVE-2022-20726

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

Mitigation only
Fix from $1,950 2022-04-15
Cgr1000 Compute Module MEDIUM 6.7
CVE-2022-20727

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

Fix: 1.4.1 / 1.15.0.1+
Fix from $1,600 2022-04-15
Yearning HIGH 7.5
CVE-2022-27043EPSS 6%

Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.

Fix: after 2.3.6
Fix from $1,950 2022-04-15
iOS MEDIUM 6.7
CVE-2022-20677

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary com…

Mitigation only
Fix from $1,600 2022-04-15
Datamodule Compactplus HIGH 8.8
CVE-2020-25150

A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and …

Mitigation only
Fix from $1,950 2022-04-14
Gocd HIGH 7.5
CVE-2021-43289

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrar…

Fix: 21.3.0+
Fix from $1,950 2022-04-14
Gocd CRITICAL 9.8
CVE-2021-43290

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory…

Fix: 21.3.0+
Fix from $2,300 2022-04-14
Gin Vue Admin HIGH 7.5
CVE-2022-24843

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arb…

Fix: 2.5.1+
Fix from $1,950 2022-04-13
Struxureware Data Center Expert CRITICAL 9.8
CVE-2021-22794

A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. …

Fix: after 7.8.1
Fix from $2,300 2022-04-13
Ecostruxure Control Expert HIGH 7.8
CVE-2021-22797EPSS 26%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be …

Fix: 15.1 / 2021+
Fix from $1,950 2022-04-13
Roothub HIGH 8.0
CVE-2022-28052

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with l…

No fix yet
Fix from $1,950 2022-04-13
Cmsimple CRITICAL 9.8
CVE-2021-43741

CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading…

No fix yet
Fix from $2,300 2022-04-13
Grunt MEDIUM 5.5
CVE-2022-0436

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

Fix: 1.5.2+
Fix from $1,600 2022-04-12
Ritecms MEDIUM 6.5
CVE-2022-24247

RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerabilit…

Fix: after 3.1.0
Fix from $1,600 2022-04-12
Ritecms MEDIUM 6.5
CVE-2022-24248EPSS 21%

RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability…

Fix: after 3.1.0
Fix from $1,600 2022-04-12
Migration\, Backup\, Staging HIGH 7.5
CVE-2022-27844

Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

Fix: 0.9.71+
Fix from $1,950 2022-04-11
Update HIGH 7.8
CVE-2022-28541

Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Upda…

Fix: 3.0.77.0+
Fix from $1,950 2022-04-11
Samsung Flow MEDIUM 5.5
CVE-2022-28543

Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.

Fix: 4.8.07.4+
Fix from $1,600 2022-04-11
Galaxy Store MEDIUM 5.5
CVE-2022-28544

Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file…

Fix: 4.5.40.5+
Fix from $1,600 2022-04-11
Android HIGH 7.8
CVE-2022-27836

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local a…

Mitigation only
Fix from $1,950 2022-04-11
4st L Bems MEDIUM 6.5
CVE-2021-37293

A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.

No fix yet
Fix from $1,600 2022-04-11
Inrouter 900 Firmware CRITICAL 9.1
CVE-2022-27277

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the fun…

Fix: 1.0.0.r11700+
Fix from $2,300 2022-04-10
Inrouter 900 Firmware HIGH 7.5
CVE-2022-27279

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.

Fix: 1.0.0.r11700+
Fix from $1,950 2022-04-10