Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.2 CVE-2023-26691 Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a … Cs Cart Multivendor No fix yet Fix from $1,9502024-09-25 HIGH 8.8 CVE-2023-26687 Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data paramete… Cs Cart Multivendor No fix yet Fix from $1,9502024-09-25 CRITICAL 9.1 CVE-2024-8671 The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in… Wooevents 4.1.3+ Fix from $2,3002024-09-24 MEDIUM 6.5 CVE-2024-43996 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inc… Elementskit after 3.6.0 Fix from $1,6002024-09-23 MEDIUM 6.5 CVE-2024-6786 The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on … Mxview One 1.4.1+ Fix from $1,6002024-09-21 MEDIUM 6.5 CVE-2024-46647 eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files. Enms 4.7.1+ Fix from $1,6002024-09-20 HIGH 7.5 CVE-2024-46648 eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder. Enms 4.7.1+ Fix from $1,9502024-09-20 HIGH 7.5 CVE-2024-46649 eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder. Enms 4.7.1+ Fix from $1,9502024-09-20 MEDIUM 6.5 CVE-2024-46644 eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file. Enms 4.7.1+ Fix from $1,6002024-09-20 HIGH 7.5 CVE-2024-46645 eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files. Enms No fix yet Fix from $1,9502024-09-20 MEDIUM 6.5 CVE-2024-46646 eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file. Enms 4.7.1+ Fix from $1,6002024-09-20 HIGH 8.8 CVE-2024-9032 A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of… Simple Forum\/discussion System No fix yet Fix from $1,9502024-09-20 CRITICAL 9.8 CVE-2024-33109 Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the p… Tiptel Ip 286 Firmware after 2.61.13.10 Fix from $2,3002024-09-19 CRITICAL 9.1 CVE-2024-8963 KEVEPSS 99% Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. Endpoint Manager Cloud Services Appliance Mitigation only Fix from $2,3002024-09-19 CRITICAL 9.8 CVE-2024-46375 Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php. Best House Rental Management System Mitigation only Fix from $2,3002024-09-18 CRITICAL 9.8 CVE-2024-46376 Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_cla… Best House Rental Management System Mitigation only Fix from $2,3002024-09-18 CRITICAL 9.9 CVE-2024-46986EPSS 37% Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upl… Camaleon Cms 2.8.2+ Fix from $2,3002024-09-18 HIGH 7.7 CVE-2024-46987EPSS 15% Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaControlle… Camaleon Cms 2.8.2+ Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-45601 Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fixed in Mesop that could poten… Patch available Fix from $1,9502024-09-18 MEDIUM 6.5 CVE-2024-45816 Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access co… Backstage 1.10.13+ Fix from $1,6002024-09-17 HIGH 7.2 CVE-2024-42501 An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install un… Mitigation only Fix from $1,9502024-09-17 HIGH 8.1 CVE-2021-27916 Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of… Mautic 4.4.12 / 5.0.4+ Fix from $1,9502024-09-17 HIGH 8.2 CVE-2024-47049 The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and make… File Handling 1.5.0 / 2.3.0+ Fix from $1,9502024-09-17 MEDIUM 5.5 CVE-2024-44190 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app … macOS 13.7 / 14.7+ Fix from $1,6002024-09-17 MEDIUM 5.5 CVE-2024-44167 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ven… Ipados 2.0 / 13.7+ Fix from $1,6002024-09-17 MEDIUM 5.5 CVE-2024-27869 The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to record the screen … Ipados 15.0 / 18.0+ Fix from $1,6002024-09-17 HIGH 7.5 CVE-2024-8752EPSS 12% The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system. Webiq No fix yet Fix from $1,9502024-09-16 MEDIUM 6.5 CVE-2024-8778 OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges t… Omflow 1.2.1.3+ Fix from $1,6002024-09-16 HIGH 7.5 CVE-2024-8876 A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown func… Tpmecms 1.3.3.2+ Fix from $1,9502024-09-15 CRITICAL 9.1 CVE-2024-8875 A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /… Wcms 0.3.2+ Fix from $2,3002024-09-15