Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2024-43957 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated Number Counters allows PHP Lo… Animated Number Counters after 1.9 Fix from $1,9502024-08-29 HIGH 7.5 CVE-2024-45436 extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory. Ollama 0.1.47+ Fix from $1,9502024-08-29 CRITICAL 9.8 CVE-2024-44761 An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests. Eq Enterprise Management System 2.0.0+ Fix from $2,3002024-08-28 MEDIUM 6.5 CVE-2024-7744 In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in… Ws Ftp Server 8.8.8+ Fix from $1,6002024-08-28 CRITICAL 9.8 CVE-2023-26321 A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltere… File Manager Mitigation only Fix from $2,3002024-08-28 MEDIUM 6.5 CVE-2024-6312 The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFo… Funnelforms Free after 3.7.3.2 Fix from $1,6002024-08-28 HIGH 7.5 CVE-2024-4556 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensi… Netiq Access Manager 5.0.4+ Fix from $1,9502024-08-28 HIGH 8.8 CVE-2024-3980 The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operat… Microscada Pro Sys600 10.6+ Fix from $1,9502024-08-27 MEDIUM 6.5 CVE-2024-6789 A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authen… M Files Server 24.2.13421.15 / 24.8.13981.0+ Fix from $1,6002024-08-27 MEDIUM 6.5 CVE-2024-8165 A vulnerability was identified in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This vulnerability affects the function exportZip of th… Beikeshop after 1.5.5 Fix from $1,6002024-08-26 HIGH 8.1 CVE-2024-8163 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function destroyFiles of the f… Beikeshop after 1.5.5 Fix from $1,9502024-08-26 HIGH 7.5 CVE-2024-45241EPSS 14% A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers t… Mitigation only Fix from $1,9502024-08-26 CRITICAL 9.8 CVE-2024-45256EPSS 6% An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and byp… Mitigation only Fix from $2,3002024-08-26 MEDIUM 6.5 CVE-2024-45189 Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Git Content" request Mage Ai No fix yet Fix from $1,6002024-08-23 MEDIUM 6.5 CVE-2024-45188 Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request Mage Ai No fix yet Fix from $1,6002024-08-23 HIGH 7.5 CVE-2023-7260 Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily acce… Cx E Voice after 22.4 Fix from $1,9502024-08-22 HIGH 7.8 CVE-2024-6141 Windscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected… Windscribe Mitigation only Fix from $1,9502024-08-21 HIGH 7.5 CVE-2024-43022 An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory trav… Mitigation only Fix from $1,9502024-08-21 HIGH 8.1 CVE-2024-7603 Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete … Unified Secops Platform Mitigation only Fix from $1,9502024-08-21 HIGH 8.1 CVE-2024-7600 Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbit… Unified Secops Platform Mitigation only Fix from $1,9502024-08-21 HIGH 8.1 CVE-2024-7601 Logsign Unified SecOps Platform Directory data_export_delete_all Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote at… Unified Secops Platform Mitigation only Fix from $1,9502024-08-21 MEDIUM 6.5 CVE-2024-7602 Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sens… Unified Secops Platform Mitigation only Fix from $1,6002024-08-21 MEDIUM 6.5 CVE-2024-7782 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is v… Contact Form Builder 2.13.5+ Fix from $1,6002024-08-20 CRITICAL 9.0 CVE-2024-7777 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is v… Contact Form Builder 2.13.10+ Fix from $2,3002024-08-20 HIGH 7.5 CVE-2024-7928EPSS 17% A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functi… Fastadmin 1.3.4.20220530+ Fix from $1,9502024-08-19 HIGH 7.5 CVE-2024-43345 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File … Mitigation only Fix from $1,9502024-08-19 HIGH 7.5 CVE-2024-7926 A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify.… Zzcms No fix yet Fix from $1,9502024-08-19 HIGH 7.5 CVE-2024-7927 A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.p… Zzcms No fix yet Fix from $1,9502024-08-19 CRITICAL 9.8 CVE-2024-43328 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusio… Embedpress 4.0.10+ Fix from $2,3002024-08-19 HIGH 7.5 CVE-2024-7924 A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manip… Zzcms No fix yet Fix from $1,9502024-08-19