Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2024-8782 A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/e… Jfinalcms after 1.0 Fix from $2,3002024-09-13 HIGH 7.5 CVE-2024-38816EPSS 15% Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An atta… No fix yet Fix from $1,9502024-09-13 CRITICAL 9.8 CVE-2024-7961 A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to th… Pavilion8 6.0+ Fix from $2,3002024-09-12 MEDIUM 6.5 CVE-2024-8706 A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/tem… Jfinalcms 20240903+ Fix from $1,6002024-09-12 HIGH 7.5 CVE-2024-7609 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal. Thi… Voc Tester 12.34.8+ Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-45593 Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR th… Nix 2.24.6+ Fix from $1,9502024-09-10 MEDIUM 6.0 CVE-2024-21753 A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 throu… Forticlient Endpoint Management Server after 7.2.4 Fix from $1,6002024-09-10 HIGH 7.5 CVE-2024-44867 phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php. Phpok No fix yet Fix from $1,9502024-09-10 HIGH 7.5 CVE-2024-37728 Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obt… No fix yet Fix from $1,9502024-09-10 HIGH 7.5 CVE-2024-44720 SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php. Seacms No fix yet Fix from $1,9502024-09-09 MEDIUM 6.5 CVE-2024-8585 Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with reg… Orca Hcm 11.0+ Fix from $1,6002024-09-09 HIGH 7.8 CVE-2024-40712 A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation … Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 7.7 CVE-2023-30584 A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handl… Mitigation only Fix from $1,9502024-09-07 MEDIUM 6.5 CVE-2024-21904 A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users … Qts Mitigation only Fix from $1,6002024-09-06 MEDIUM 6.5 CVE-2023-51366 A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users … Qts Mitigation only Fix from $1,6002024-09-06 HIGH 7.5 CVE-2024-6445 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal… Datadiodex 3.1.7+ Fix from $1,9502024-09-06 HIGH 7.1 CVE-2024-45401 stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to vers… Stripe Cli 1.21.3+ Fix from $1,9502024-09-05 HIGH 8.8 CVE-2024-45175 An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive… C Mor Video Surveillance No fix yet Fix from $1,9502024-09-05 HIGH 7.1 CVE-2024-45178 An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary f… C Mor Video Surveillance No fix yet Fix from $1,9502024-09-05 MEDIUM 6.5 CVE-2024-45074 IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted … Webmethods Integration Mitigation only Fix from $1,6002024-09-04 HIGH 7.5 CVE-2024-8410 A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/… Abcd Mitigation only Fix from $1,9502024-09-04 HIGH 7.5 CVE-2024-8409 A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_imag… Abcd Mitigation only Fix from $1,9502024-09-04 MEDIUM 6.5 CVE-2024-8104 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.… Wp Extended 3.0.9+ Fix from $1,6002024-09-04 HIGH 7.8 CVE-2024-34656 Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code. Notes 4.4.21.62+ Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-7950 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitr… Wp Job Portal 2.1.7+ Fix from $2,3002024-09-04 CRITICAL 9.1 CVE-2024-45443 Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiali… Emui Mitigation only Fix from $2,3002024-09-04 HIGH 7.5 CVE-2024-45388EPSS 56% Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler… Hoverfly 1.10.3+ Fix from $1,9502024-09-02 MEDIUM 5.3 CVE-2024-45312 Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) co… Overleaf 4.2.7 / 5.0.7+ Fix from $1,6002024-09-02 HIGH 7.5 CVE-2024-42471 actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable t… Actions\/artifact 2.1.7+ Fix from $1,9502024-09-02 HIGH 7.5 CVE-2024-43955 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows File Manipulation.This issue aff… Droip after 1.1.1 Fix from $1,9502024-08-29