Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Advanced Access Manager HIGH 7.5
CVE-2019-25213

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due t…

Fix: after 5.9.8.1
Fix from $1,950 2024-10-16
Unclassified CRITICAL 9.1
CVE-2024-48914EPSS 60%

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an a…

Patch available
Fix from $2,300 2024-10-15
Openshift Container Platform MEDIUM 6.5
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda…

Patch available
Fix from $1,600 2024-10-15
Enterprise Cloud Database HIGH 7.5
CVE-2024-9983

Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this …

Fix: 2024-08-08+
Fix from $1,950 2024-10-15
Shirasagi HIGH 7.5
CVE-2024-46898

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploite…

Fix: 1.19.1+
Fix from $1,950 2024-10-15
Nemo HIGH 7.8
CVE-2024-0129

NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A succ…

Mitigation only
Fix from $1,950 2024-10-15
Splunk HIGH 8.0
CVE-2024-45731

In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles…

Fix: 9.1.6 / 9.2.3+
Fix from $1,950 2024-10-14
Wordpress File Upload CRITICAL 9.8
CVE-2024-9047EPSS 93%

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.…

Fix: 4.24.12+
Fix from $2,300 2024-10-12
Extract HIGH 7.5
CVE-2024-47877

Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symli…

Fix: 4.0.0+
Fix from $1,950 2024-10-11
Unclassified MEDIUM 6.5
CVE-2024-7514

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during t…

Mitigation only
Fix from $1,600 2024-10-11
Gradio HIGH 7.5
CVE-2024-47868

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio componen…

Fix: 5.0.0+
Fix from $1,950 2024-10-10
Gradio MEDIUM 6.5
CVE-2024-47164

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** wi…

Fix: 5.0.0+
Fix from $1,600 2024-10-10
Gradio MEDIUM 5.3
CVE-2024-47166

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/cust…

Fix: 4.44.0+
Fix from $1,600 2024-10-10
Open Webui HIGH 7.2
CVE-2024-7037

In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized fi…

No fix yet
Fix from $1,950 2024-10-09
Unclassified HIGH 8.5
CVE-2024-9575

Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pre…

Mitigation only
Fix from $1,950 2024-10-09
Unclassified HIGH 7.1
CVE-2024-47191

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, …

Patch available
Fix from $1,950 2024-10-09
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9381EPSS 16%

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Avalanche CRITICAL 9.8
CVE-2024-47010EPSS 38%

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Fix: 6.4.5+
Fix from $2,300 2024-10-08
Avalanche HIGH 7.5
CVE-2024-47011EPSS 56%

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

Fix: 6.4.5+
Fix from $1,950 2024-10-08
Avalanche CRITICAL 9.8
CVE-2024-47009

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Fix: 6.4.5+
Fix from $2,300 2024-10-08
Teamcity HIGH 7.5
CVE-2024-47948

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

Fix: 2024.07.3+
Fix from $1,950 2024-10-08
Teamcity HIGH 7.5
CVE-2024-47949EPSS 23%

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Fix: 2024.07.3+
Fix from $1,950 2024-10-08
Sinec Security Monitor MEDIUM 5.3
CVE-2024-47563

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file pat…

Fix: 4.9.0+
Fix from $1,600 2024-10-08
Unclassified MEDIUM 6.5
CVE-2024-47818

Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesy…

Patch available
Fix from $1,600 2024-10-07
Phpspreadsheet HIGH 8.8
CVE-2024-45291

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links im…

Fix: 1.29.2 / 2.1.1+
Fix from $1,950 2024-10-07
Freeflow Core CRITICAL 9.8
CVE-2024-47556

Pre-Auth RCE via Path Traversal

Fix: 7.0.11+
Fix from $2,300 2024-10-07
Freeflow Core CRITICAL 9.8
CVE-2024-47557

Pre-Auth RCE via Path Traversal

Fix: 7.0.11+
Fix from $2,300 2024-10-07
Freeflow Core HIGH 8.8
CVE-2024-47558

Authenticated RCE via Path Traversal

Mitigation only
Fix from $1,950 2024-10-07
Freeflow Core HIGH 8.8
CVE-2024-47559

Authenticated RCE via Path Traversal

Mitigation only
Fix from $1,950 2024-10-07
Mecha CRITICAL 9.8
CVE-2024-46446

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can the…

No fix yet
Fix from $2,300 2024-10-07