Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Moodle HIGH 7.5
CVE-2024-43440

A flaw was found in moodle. A local file may include risks when restoring block backups.

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Unclassified CRITICAL 9.3
CVE-2024-51990

jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outsid…

Mitigation only
Fix from $2,300 2024-11-07
Gradio MEDIUM 6.5
CVE-2024-51751

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as …

Fix: 5.5.0+
Fix from $1,600 2024-11-06
Identity Services Engine MEDIUM 5.5
CVE-2024-20532

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To ex…

Fix: 3.1.0+
Fix from $1,600 2024-11-06
Identity Services Engine MEDIUM 5.5
CVE-2024-20527

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To ex…

Fix: 3.1.0+
Fix from $1,600 2024-11-06
Identity Services Engine HIGH 7.2
CVE-2024-20528

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operat…

Fix: 3.1.0+
Fix from $1,950 2024-11-06
Identity Services Engine MEDIUM 5.5
CVE-2024-20529

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To ex…

Fix: 3.1.0+
Fix from $1,600 2024-11-06
Unclassified MEDIUM 6.8
CVE-2024-47464

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to…

Mitigation only
Fix from $1,600 2024-11-05
Access Commander HIGH 7.2
CVE-2024-47253

In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write fil…

Fix: after 3.1.1.2
Fix from $1,950 2024-11-05
Hornetq HIGH 7.1
CVE-2024-51127

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

Fix: after 2.4.9
Fix from $1,950 2024-11-04
Wp Hotel Booking HIGH 8.8
CVE-2024-51582

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel …

Fix: after 2.1.4
Fix from $1,950 2024-11-04
Safearchive HIGH 7.5
CVE-2024-10389

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Writ…

Fix: 2024-10-25+
Fix from $1,950 2024-11-04
Unclassified MEDIUM 6.9
CVE-2024-51483

changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source…

Mitigation only
Fix from $1,600 2024-11-01
Unclassified HIGH 7.7
CVE-2024-49770

`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does…

Patch available
Fix from $1,950 2024-11-01
Unclassified HIGH 8.5
CVE-2024-37423

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This…

Mitigation only
Fix from $1,950 2024-11-01
Unclassified HIGH 7.7
CVE-2024-37108

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Trave…

Mitigation only
Fix from $1,950 2024-11-01
Ollama HIGH 7.5
CVE-2024-39722

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/pus…

Fix: 0.1.46+
Fix from $1,950 2024-10-31
Webswing CRITICAL 9.8
CVE-2024-39332

Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via …

No fix yet
Fix from $2,300 2024-10-31
Consul MEDIUM 5.8
CVE-2024-10005

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP reques…

Fix: 1.15.15 / 1.18.5+
Fix from $1,600 2024-10-30
Unclassified HIGH 7.7
CVE-2024-48735

Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal f…

Mitigation only
Fix from $1,950 2024-10-30
Unclassified HIGH 7.5
CVE-2024-50508

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product…

Mitigation only
Fix from $1,950 2024-10-30
Unclassified HIGH 8.6
CVE-2024-50509

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product…

Mitigation only
Fix from $1,950 2024-10-30
Chuanhuchatgpt HIGH 7.5
CVE-2024-7962

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt templat…

Patch available
Fix from $1,950 2024-10-29
Langchain.js CRITICAL 9.1
CVE-2024-7774

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to s…

Patch available
Fix from $2,300 2024-10-29
Chuanhuchatgpt CRITICAL 9.8
CVE-2024-5982EPSS 31%

A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling i…

Fix: 20240918+
Fix from $2,300 2024-10-29
Ipados HIGH 7.8
CVE-2024-44255

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, ma…

Fix: 2.1 / 11.1+
Fix from $1,950 2024-10-28
The Pack Elementor Addons HIGH 8.8
CVE-2024-50453

Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pac…

Fix: 2.1.0+
Fix from $1,950 2024-10-28
Unclassified MEDIUM 5.3
CVE-2024-49771

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerabili…

Patch available
Fix from $1,600 2024-10-28
Werkzeug MEDIUM 5.3
CVE-2024-49766

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //serv…

Fix: 3.0.6+
Fix from $1,600 2024-10-25
Mango HIGH 8.8
CVE-2024-37847

An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted fi…

Fix: 4.5.5 / 5.1.4+
Fix from $1,950 2024-10-25