Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified HIGH 7.5
CVE-2024-44034

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File In…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified MEDIUM 6.6
CVE-2024-47309

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Condless Cities Shipping Zones for WooCommerce cities…

Mitigation only
Fix from $1,600 2024-10-05
Unclassified HIGH 7.5
CVE-2024-44018

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPre…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified HIGH 7.5
CVE-2024-44016

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File I…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified HIGH 7.5
CVE-2024-44011

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Suppo…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified HIGH 7.5
CVE-2024-44012

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subs…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified HIGH 7.5
CVE-2024-44013

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified CRITICAL 9.6
CVE-2024-44014

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager…

Mitigation only
Fix from $2,300 2024-10-05
Unclassified HIGH 7.5
CVE-2024-44015

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP L…

Mitigation only
Fix from $1,950 2024-10-05
Wikimedia Extensions Css HIGH 7.5
CVE-2024-47841EPSS 35%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension al…

Fix: 1.39.9 / 1.41.3+
Fix from $1,950 2024-10-05
Idurar HIGH 7.5
CVE-2024-47769

IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here…

Fix: after 4.1.0
Fix from $1,950 2024-10-04
Anka Build Cloud HIGH 7.5
CVE-2024-41163EPSS 52%

A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a d…

No fix yet
Fix from $1,950 2024-10-03
Anka Build Cloud HIGH 7.5
CVE-2024-41922EPSS 8%

A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can …

No fix yet
Fix from $1,950 2024-10-03
Unclassified MEDIUM 6.5
CVE-2024-9100

Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

Mitigation only
Fix from $1,600 2024-10-03
Social Web Suite HIGH 7.5
CVE-2024-8352

The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up…

Fix: 4.1.12+
Fix from $1,950 2024-10-03
Cosmos MEDIUM 6.5
CVE-2024-46977

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerabilit…

Fix: 5.19.0+
Fix from $1,600 2024-10-02
Nexus Dashboard Fabric Controller HIGH 8.8
CVE-2024-20449

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitr…

Fix: after 12.2.2
Fix from $1,950 2024-10-02
Unclassified HIGH 7.5
CVE-2024-44017

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File…

Mitigation only
Fix from $1,950 2024-10-02
Unclassified HIGH 7.2
CVE-2024-44030

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp…

Mitigation only
Fix from $1,950 2024-10-02
Transcend Network Management System HIGH 7.2
CVE-2024-25659

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows…

Mitigation only
Fix from $1,950 2024-10-01
Unclassified MEDIUM 6.8
CVE-2024-47071

OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized…

Patch available
Fix from $1,600 2024-10-01
Hello World MEDIUM 6.5
CVE-2024-9224

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() …

Fix: 2.2.0+
Fix from $1,600 2024-10-01
Rpshare HIGH 8.8
CVE-2024-33369

Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromC…

Mitigation only
Fix from $1,950 2024-09-27
E2nest HIGH 7.5
CVE-2024-9301

A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a

Fix: 2024-09-05+
Fix from $1,950 2024-09-27
Eventin HIGH 8.8
CVE-2024-7149

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…

Fix: 4.0.9+
Fix from $1,950 2024-09-27
Emui MEDIUM 5.5
CVE-2024-47292

Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2024-09-27
Vap11g 300 Firmware MEDIUM 5.7
CVE-2024-46327

An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.

Mitigation only
Fix from $1,600 2024-09-26
Advanced File Manager HIGH 7.2
CVE-2024-8704

The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the '…

Fix: 5.2.9+
Fix from $1,950 2024-09-26
Unclassified HIGH 7.5
CVE-2024-44825

Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files…

Mitigation only
Fix from $1,950 2024-09-25
Scriptcase MEDIUM 5.3
CVE-2024-8941

Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allo…

Mitigation only
Fix from $1,600 2024-09-25