Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Ng Firewall HIGH 7.3
CVE-2024-12830

Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2024-12-20
Unclassified HIGH 7.5
CVE-2024-38819EPSS 55%

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An atta…

Mitigation only
Fix from $1,950 2024-12-19
Fortiwan CRITICAL 9.1
CVE-2021-26102EPSS 17%

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker …

Fix: 4.5.8+
Fix from $2,300 2024-12-19
Unclassified HIGH 7.5
CVE-2024-21547

Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:…

Patch available
Fix from $1,950 2024-12-18
Unclassified MEDIUM 6.5
CVE-2024-56142

pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerability has been discovered that co…

Mitigation only
Fix from $1,600 2024-12-17
Msg2300 Firmware CRITICAL 9.1
CVE-2024-55516

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on…

Mitigation only
Fix from $2,300 2024-12-17
Msg2300 Firmware CRITICAL 9.1
CVE-2024-55513

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on …

Mitigation only
Fix from $2,300 2024-12-17
Msg2300 Firmware CRITICAL 9.8
CVE-2024-55515

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the…

Mitigation only
Fix from $2,300 2024-12-17
Unclassified HIGH 7.5
CVE-2024-54380

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies Enabler wp-cookies-enabler a…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.5
CVE-2024-54373

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmin Booking eduadmin-booking al…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.5
CVE-2024-54374

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allows PHP Local File Inclusion.T…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.5
CVE-2024-54375

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Woolook woolook allows PHP Local File Inclusion…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.5
CVE-2024-55970

File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I64473…

Mitigation only
Fix from $1,950 2024-12-15
Unclassified MEDIUM 6.5
CVE-2024-54259

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Path Traversal…

Mitigation only
Fix from $1,600 2024-12-13
Plextrac CRITICAL 9.1
CVE-2024-11833

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affe…

Fix: 2.8.1+
Fix from $2,300 2024-12-13
Plextrac CRITICAL 9.1
CVE-2024-11834

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affe…

Fix: 2.8.1+
Fix from $2,300 2024-12-13
GitLab MEDIUM 5.4
CVE-2024-8647

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted inst…

Fix: 17.4.6 / 17.5.4+
Fix from $1,600 2024-12-12
Siyuan HIGH 7.5
CVE-2024-55657

SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/ren…

Patch available
Fix from $1,950 2024-12-12
Siyuan HIGH 7.5
CVE-2024-55658

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary fi…

Patch available
Fix from $1,950 2024-12-12
Siyuan MEDIUM 5.4
CVE-2024-55659

SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary…

Patch available
Fix from $1,600 2024-12-12
macOS HIGH 7.8
CVE-2024-54489

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. R…

Fix: 13.7.2 / 14.7.2+
Fix from $1,950 2024-12-12
Unclassified HIGH 8.8
CVE-2024-55587

python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.

Patch available
Fix from $1,950 2024-12-12
Windows 10 1507 MEDIUM 6.8
CVE-2024-49082

Windows File Explorer Information Disclosure Vulnerability

Fix: 10.0.10240.20857 / 10.0.14393.7606+
Fix from $1,600 2024-12-12
Pwndoc HIGH 8.5
CVE-2024-55602

PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update …

Fix: after 1.2.1
Fix from $1,950 2024-12-10
Web Help Desk MEDIUM 5.5
CVE-2024-45709

SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and conf…

Fix: 12.8.4+
Fix from $1,600 2024-12-10
Foogallery HIGH 7.7
CVE-2023-6947

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26…

Fix: 2.4.27+
Fix from $1,950 2024-12-10
Unclassified HIGH 8.6
CVE-2024-21542

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file …

Patch available
Fix from $1,950 2024-12-10
Connectport Lts Firmware HIGH 8.8
CVE-2024-50626

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the lo…

Fix: 1.4.12+
Fix from $1,950 2024-12-09
Unclassified HIGH 7.5
CVE-2024-53790

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS lenxel-core…

Mitigation only
Fix from $1,950 2024-12-09
Unclassified HIGH 7.2
CVE-2024-11010

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a…

Mitigation only
Fix from $1,950 2024-12-07