Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Plenti HIGH 7.5
CVE-2024-49381

Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to …

Fix: 0.7.2+
Fix from $1,950 2024-10-25
Cdg HIGH 7.5
CVE-2024-10379

A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the fil…

No fix yet
Fix from $1,950 2024-10-25
Android HIGH 7.8
CVE-2024-47027

In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This coul…

Mitigation only
Fix from $1,950 2024-10-25
E Studio1058 Firmware MEDIUM 5.3
CVE-2024-45842

Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files m…

Mitigation only
Fix from $1,600 2024-10-25
Buddypress HIGH 8.1
CVE-2024-10011

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This make…

Fix: after 14.1.0
Fix from $1,950 2024-10-25
Zimaos HIGH 7.5
CVE-2024-49359

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpo…

Fix: 1.2.5+
Fix from $1,950 2024-10-24
Openrefine MEDIUM 5.3
CVE-2024-49760

OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the…

Fix: 3.8.3+
Fix from $1,600 2024-10-24
Zimaos HIGH 7.5
CVE-2024-48931

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS AP…

Fix: 1.2.5+
Fix from $1,950 2024-10-24
Butterfly CRITICAL 9.1
CVE-2024-47883

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class …

Fix: after 1.2.6
Fix from $2,300 2024-10-24
Mt2500 Firmware HIGH 8.8
CVE-2024-45262

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call met…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Unclassified HIGH 8.0
CVE-2024-10313

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template f…

Mitigation only
Fix from $1,950 2024-10-24
Firepower Management Center MEDIUM 6.5
CVE-2024-20379

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…

Mitigation only
Fix from $1,600 2024-10-23
Unclassified CRITICAL 9.8
CVE-2024-41717

Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the sy…

Mitigation only
Fix from $2,300 2024-10-22
Pandora Fms HIGH 8.8
CVE-2024-35308

A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: …

Fix: 777.3+
Fix from $1,950 2024-10-22
Micollab CRITICAL 9.1
CVE-2024-41713 KEVEPSS 98%

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated att…

Fix: after 9.8.1.201
Fix from $2,300 2024-10-21
Nginx Ui HIGH 7.5
CVE-2024-49366

Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verificatio…

Fix: after 1.9.9-4
Fix from $1,950 2024-10-21
Onedev HIGH 7.5
CVE-2024-45309EPSS 25%

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary f…

Fix: 11.0.9+
Fix from $1,950 2024-10-21
Debian Linux HIGH 7.8
CVE-2024-47742

In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Block path traversal Most firmware names are hardcoded strings…

Fix: 4.19.323 / 5.4.285+
Fix from $1,950 2024-10-21
Administrative Management System HIGH 7.5
CVE-2024-10200

Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner…

Mitigation only
Fix from $1,950 2024-10-21
Ssv Events CRITICAL 9.8
CVE-2024-49286

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Events ssv-events allows PHP Loca…

Fix: after 3.2.7
Fix from $2,300 2024-10-20
Gpt Academic HIGH 7.5
CVE-2024-10100

A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of the file parameter,…

No fix yet
Fix from $1,950 2024-10-17
Unclassified HIGH 7.5
CVE-2024-49285

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV MailChimp ssv-mailchimp allows PH…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 7.5
CVE-2024-49287

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Rechnungsverwaltung pdf-rechnun…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 8.6
CVE-2024-49315

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 7.5
CVE-2024-49245

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.T…

Mitigation only
Fix from $1,950 2024-10-16
Litespeed Cache HIGH 8.8
CVE-2024-47637

Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca…

Fix: 6.5.1+
Fix from $1,950 2024-10-16
Unclassified HIGH 7.5
CVE-2024-47645

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpopti…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified HIGH 7.5
CVE-2024-47351

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path T…

Mitigation only
Fix from $1,950 2024-10-16
Serv U HIGH 8.8
CVE-2024-45711EPSS 6%

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the…

Fix: 15.5+
Fix from $1,950 2024-10-16
Wp Fastest Cache HIGH 8.0
CVE-2020-36836

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a la…

Fix: 0.9.0.3+
Fix from $1,950 2024-10-16