Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 8.6
CVE-2024-52371

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway e4 | Payeezy Gateway | globe-…

Mitigation only
Fix from $1,950 2024-11-14
Eyoucms MEDIUM 5.4
CVE-2024-11210

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi…

No fix yet
Fix from $1,600 2024-11-14
User Registration \& Login And User Management System MEDIUM 5.3
CVE-2024-50843

A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to…

No fix yet
Fix from $1,600 2024-11-14
Webserver MEDIUM 6.5
CVE-2024-11215

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. …

Mitigation only
Fix from $1,600 2024-11-14
Unclassified HIGH 7.5
CVE-2024-47916

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Mitigation only
Fix from $1,950 2024-11-14
Unclassified HIGH 7.5
CVE-2024-45253

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Mitigation only
Fix from $1,950 2024-11-14
Pan Os MEDIUM 6.0
CVE-2024-2552

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the m…

Fix: 10.2.7 / 11.0.6+
Fix from $1,600 2024-11-14
Unclassified HIGH 7.1
CVE-2024-21799

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalat…

Mitigation only
Fix from $1,950 2024-11-13
Craft Cms HIGH 7.2
CVE-2024-52291

Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a doub…

Fix: 4.12.5 / 5.4.6+
Fix from $1,950 2024-11-13
Craft Cms MEDIUM 6.5
CVE-2024-52292

Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templat…

Fix: 4.12.8 / 5.4.9+
Fix from $1,600 2024-11-13
Craft Cms HIGH 7.2
CVE-2024-52293

Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could …

Fix: 4.12.2 / 5.4.3+
Fix from $1,950 2024-11-13
Prodotnetzip CRITICAL 9.8
CVE-2024-48510

Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry…

Fix: 1.19.0+
Fix from $2,300 2024-11-13
User Extra Fields CRITICAL 9.8
CVE-2024-11150

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_…

Fix: 16.7+
Fix from $2,300 2024-11-13
Unclassified HIGH 7.5
CVE-2024-10816

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.…

Mitigation only
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.8
CVE-2024-34787EPSS 18%

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at…

Fix: 2022+
Fix from $1,950 2024-11-13
Fortianalyzer MEDIUM 6.0
CVE-2024-32116

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer versio…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2024-11-12
Unclassified MEDIUM 5.3
CVE-2024-50336

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path travers…

Mitigation only
Fix from $1,600 2024-11-12
Endpoint Manager HIGH 8.8
CVE-2024-50329

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated a…

Fix: 2022+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.8
CVE-2024-50322EPSS 6%

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at…

Fix: 2022+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.2
CVE-2024-50324EPSS 19%

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated att…

Fix: 2022+
Fix from $1,950 2024-11-12
Sinec Ins CRITICAL 9.9
CVE-2024-46888

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provide…

Fix: 1.0+
Fix from $2,300 2024-11-12
Lingdang Crm HIGH 7.5
CVE-2024-11123

A vulnerability, which was classified as problematic, was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. This affects an unknown part …

Fix: after 8.6.4.3
Fix from $1,950 2024-11-12
Kanboard HIGH 7.2
CVE-2024-51747

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files f…

Fix: 1.2.42+
Fix from $1,950 2024-11-11
Kanboard HIGH 7.2
CVE-2024-51748

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the ser…

Fix: 1.2.42+
Fix from $1,950 2024-11-11
Ghostscript HIGH 7.8
CVE-2024-46954

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directo…

Fix: 10.04.0+
Fix from $1,950 2024-11-10
Wordpress Learning Management System CRITICAL 9.8
CVE-2024-10470EPSS 34%

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insuff…

Fix: 4.963+
Fix from $2,300 2024-11-09
Woocommerce Support Ticket System CRITICAL 9.1
CVE-2024-10625

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d…

Fix: 17.8+
Fix from $2,300 2024-11-09
Woocommerce Support Ticket System HIGH 8.1
CVE-2024-10626

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d…

Fix: 17.8+
Fix from $1,950 2024-11-09
Unclassified HIGH 8.6
CVE-2024-51998

changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attack…

Patch available
Fix from $1,950 2024-11-08
Moodle HIGH 8.1
CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerabil…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07