Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.1
CVE-2024-10516EPSS 6%

The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajax…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified HIGH 7.5
CVE-2024-11585

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficien…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified HIGH 7.5
CVE-2024-53523

JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.

Mitigation only
Fix from $1,950 2024-12-05
OpenBSD MEDIUM 5.5
CVE-2024-10933

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversa…

Fix: 7.4+
Fix from $1,600 2024-12-05
Unclassified HIGH 7.5
CVE-2024-53490

Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.

Mitigation only
Fix from $1,950 2024-12-05
Aspect Ent 12 Firmware CRITICAL 9.4
CVE-2024-51549

Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.  Affected products: ABB ASPECT - Enterprise v3.08…

Fix: 3.08.03+
Fix from $2,300 2024-12-05
Unclassified MEDIUM 6.3
CVE-2024-54132

The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite file…

Patch available
Fix from $1,600 2024-12-04
Youtrack CRITICAL 9.8
CVE-2024-54154

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

Fix: 2024.3.51866+
Fix from $2,300 2024-12-04
Unclassified HIGH 7.5
CVE-2024-11952

The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and includin…

Mitigation only
Fix from $1,950 2024-12-04
Router Manager HIGH 8.1
CVE-2024-11398

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (S…

Fix: 1.3.1-9346+
Fix from $1,950 2024-12-04
Debian Linux MEDIUM 5.5
CVE-2024-53566

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path …

Mitigation only
Fix from $1,600 2024-12-02
Whatsup Gold CRITICAL 9.8
CVE-2024-46909EPSS 49%

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context…

Fix: 24.0.1+
Fix from $2,300 2024-12-02
Sandboxie HIGH 8.4
CVE-2024-49360

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (**UserA**) with no p…

Fix: 1.14.6 / 5.69.6+
Fix from $1,950 2024-11-29
Unclassified CRITICAL 9.1
CVE-2024-11992

Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictio…

Mitigation only
Fix from $2,300 2024-11-29
Enterprise Security Manager HIGH 8.2
CVE-2024-11481

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, inse…

Mitigation only
Fix from $1,950 2024-11-29
Jobify HIGH 7.5
CVE-2024-52481

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify jobify allows Relative Path Travers…

Fix: 4.2.4+
Fix from $1,950 2024-11-28
Filester HIGH 7.2
CVE-2024-9669

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via…

Fix: 1.8.6+
Fix from $1,950 2024-11-28
Zld CRITICAL 9.8
CVE-2024-11667 KEV

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwa…

Fix: after 5.38
Fix from $2,300 2024-11-27
Otter Blocks HIGH 7.5
CVE-2024-11219

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up …

Fix: 3.0.7+
Fix from $1,950 2024-11-27
Insight Remote Support CRITICAL 9.8
CVE-2024-53676EPSS 52%

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

Fix: 7.14.0.629+
Fix from $2,300 2024-11-27
Unclassified MEDIUM 6.3
CVE-2024-53844

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup ex…

Mitigation only
Fix from $1,600 2024-11-26
Unclassified HIGH 7.5
CVE-2024-33605EPSS 6%

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product…

No fix yet
Fix from $1,950 2024-11-26
Unclassified CRITICAL 9.1
CVE-2024-52787

An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uplo…

Patch available
Fix from $2,300 2024-11-25
Enms CRITICAL 9.8
CVE-2024-11664

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of …

Fix: 4.2+
Fix from $2,300 2024-11-25
Unclassified HIGH 7.5
CVE-2024-10803

The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.…

Mitigation only
Fix from $1,950 2024-11-23
Soapui HIGH 7.8
CVE-2024-7565

SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2024-11-22
Allegra HIGH 7.2
CVE-2024-5581

Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…

Fix: 7.5.2+
Fix from $1,950 2024-11-22
Allegra MEDIUM 6.5
CVE-2023-51648

Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensi…

Fix: 7.5.1+
Fix from $1,600 2024-11-22
Allegra HIGH 7.5
CVE-2023-52332

Allegra serveMathJaxLibraries Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensit…

Fix: 7.5.1+
Fix from $1,950 2024-11-22
Allegra HIGH 7.3
CVE-2023-52333

Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…

Fix: 7.5.1+
Fix from $1,950 2024-11-22