Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.3
CVE-2024-42187

BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local re…

Mitigation only
Fix from $1,600 2025-01-23
Unclassified MEDIUM 5.8
CVE-2025-23562

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.…

No fix yet
Fix from $1,600 2025-01-22
Yeswiki HIGH 7.1
CVE-2025-24019

YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the fil…

Fix: 4.5.0+
Fix from $1,950 2025-01-21
Unclassified MEDIUM 5.3
CVE-2025-0614

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper a…

Mitigation only
Fix from $1,600 2025-01-21
Unclassified MEDIUM 5.3
CVE-2025-0615

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an attacker to modify an email to contain the ‘+’ symbol to …

Mitigation only
Fix from $1,600 2025-01-21
Maximo Asset Management HIGH 7.5
CVE-2024-45652

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…

Mitigation only
Fix from $1,950 2025-01-19
Eventer MEDIUM 6.5
CVE-2024-10799

The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_ticket…

Fix: 3.9.8+
Fix from $1,600 2025-01-17
Infosphere Information Server HIGH 7.5
CVE-2024-52363

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…

Mitigation only
Fix from $1,950 2025-01-17
Unclassified MEDIUM 5.5
CVE-2024-57784

An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.

Mitigation only
Fix from $1,600 2025-01-16
Fortirecorder CRITICAL 9.1
CVE-2024-48885

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRe…

Fix: 7.0.5 / 7.2.2+
Fix from $2,300 2025-01-16
Simplehelp HIGH 7.5
CVE-2024-57727 KEVEPSS 95%

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote atta…

Fix: 5.5.8+
Fix from $1,950 2025-01-15
Simplehelp HIGH 7.2
CVE-2024-57728 KEVEPSS 7%

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted …

Fix: 5.5.8+
Fix from $1,950 2025-01-15
Elementinvader Addons For Elementor HIGH 8.8
CVE-2025-22786

Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local…

Fix: 1.2.7+
Fix from $1,950 2025-01-15
Endpoint Manager HIGH 7.2
CVE-2024-13158

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remot…

Fix: 2024+
Fix from $1,950 2025-01-14
Arch Linux HIGH 7.5
CVE-2024-12087

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many cli…

No fix yet
Fix from $1,950 2025-01-14
Discovery HIGH 7.5
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t…

Mitigation only
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.5
CVE-2024-10811

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Avalanche CRITICAL 9.8
CVE-2024-13179EPSS 62%

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

Fix: 6.4.7+
Fix from $2,300 2025-01-14
Avalanche HIGH 7.5
CVE-2024-13180EPSS 28%

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses in…

Fix: 6.4.7+
Fix from $1,950 2025-01-14
Avalanche CRITICAL 9.8
CVE-2024-13181EPSS 32%

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incompl…

Fix: 6.4.6+
Fix from $2,300 2025-01-14
Lingdang Crm HIGH 7.5
CVE-2025-0461

A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as problematic. This vulnerabili…

Mitigation only
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39786

Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted H…

No fix yet
Fix from $1,950 2025-01-14
Wl Wn533a8 Firmware HIGH 7.2
CVE-2024-39787

Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted H…

No fix yet
Fix from $1,950 2025-01-14
Fortirecorder MEDIUM 6.0
CVE-2024-47566

A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and b…

Fix: 7.0.5 / 7.2.2+
Fix from $1,600 2025-01-14
Fortimanager CRITICAL 9.1
CVE-2024-48884EPSS 15%

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiMan…

Fix: 6.4.16 / 7.0.5+
Fix from $2,300 2025-01-14
Fortianalyzer HIGH 7.2
CVE-2024-36512

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2…

Fix: 7.0.13 / 7.2.6+
Fix from $1,950 2025-01-14
Fortimanager MEDIUM 5.5
CVE-2024-32115

A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker …

Fix: 7.2.6 / 7.4.3+
Fix from $1,600 2025-01-14
Fortianalyzer HIGH 7.2
CVE-2024-33502

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.…

Fix: 7.2.6 / 7.4.3+
Fix from $1,950 2025-01-14
Unclassified MEDIUM 6.6
CVE-2024-12083

Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform un…

Mitigation only
Fix from $1,600 2025-01-14
Helpdeskadvanced HIGH 7.5
CVE-2023-42232

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13