Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Allegra MEDIUM 6.5
CVE-2023-52334

Allegra downloadAttachmentGlobal Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sen…

Fix: 7.5.1+
Fix from $1,600 2024-11-22
Allegra CRITICAL 9.8
CVE-2023-51639

Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentic…

Fix: 7.5.1+
Fix from $2,300 2024-11-22
Unclassified HIGH 8.1
CVE-2024-10220

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11…

Mitigation only
Fix from $1,950 2024-11-22
Streaming Engine MEDIUM 6.5
CVE-2024-52056

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system…

Fix: 4.9.1+
Fix from $1,600 2024-11-21
Dedebiz CRITICAL 9.1
CVE-2024-52771

DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

No fix yet
Fix from $2,300 2024-11-20
Unclassified HIGH 7.5
CVE-2024-52448

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified HIGH 7.5
CVE-2024-52449

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscraper allows PHP Local File Incl…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified HIGH 7.5
CVE-2024-52444

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-cus…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified MEDIUM 5.3
CVE-2024-52600

Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames…

Patch available
Fix from $1,600 2024-11-19
E Cology MEDIUM 6.5
CVE-2024-48071

E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to pe…

Mitigation only
Fix from $1,600 2024-11-19
Data Center Network Manager HIGH 8.1
CVE-2020-3538

A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacke…

Fix: 11.4+
Fix from $1,950 2024-11-18
Catalyst Sd Wan Manager HIGH 8.4
CVE-2020-26071

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an af…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified HIGH 8.7
CVE-2024-11303

The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issu…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified HIGH 8.1
CVE-2024-41971

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

No fix yet
Fix from $1,950 2024-11-18
Dvc CRITICAL 9.8
CVE-2024-11315

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker…

Fix: 6.4+
Fix from $2,300 2024-11-18
Dvc CRITICAL 9.8
CVE-2024-11313

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker…

Fix: 6.4+
Fix from $2,300 2024-11-18
Dvc CRITICAL 9.8
CVE-2024-11314

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker…

Fix: 6.4+
Fix from $2,300 2024-11-18
Dvc CRITICAL 9.8
CVE-2024-11312

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker…

Fix: 6.4+
Fix from $2,300 2024-11-18
Dvc CRITICAL 9.8
CVE-2024-11311

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker…

Fix: 6.4+
Fix from $2,300 2024-11-18
Dvc HIGH 7.5
CVE-2024-11309

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary sys…

Fix: 6.4+
Fix from $1,950 2024-11-18
Dvc HIGH 7.5
CVE-2024-11310

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary sys…

Fix: 6.4+
Fix from $1,950 2024-11-18
Unclassified HIGH 7.5
CVE-2024-9935EPSS 7%

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 v…

Mitigation only
Fix from $1,950 2024-11-16
Gogs HIGH 8.8
CVE-2024-44625EPSS 15%

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Fix: after 0.13.0
Fix from $1,950 2024-11-15
Yshopmall CRITICAL 9.8
CVE-2024-50648

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP …

No fix yet
Fix from $2,300 2024-11-15
Python Book CRITICAL 9.8
CVE-2024-50649

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

No fix yet
Fix from $2,300 2024-11-15
Sterling Secure Proxy HIGH 7.5
CVE-2024-41784

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An att…

Mitigation only
Fix from $1,950 2024-11-15
Landray Ekp MEDIUM 5.3
CVE-2024-11238EPSS 6%

A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/…

Fix: after 16.0
Fix from $1,600 2024-11-15
Unclassified MEDIUM 5.3
CVE-2024-42499

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerabi…

Mitigation only
Fix from $1,600 2024-11-15
Wolf Wordpress Posts Bulk Editor And Products Manager Professional HIGH 8.8
CVE-2024-52396

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.Thi…

Fix: 1.0.8.4+
Fix from $1,950 2024-11-14
Unclassified HIGH 7.5
CVE-2024-52378

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass allows Absolute Path Travers…

Mitigation only
Fix from $1,950 2024-11-14