Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2024-33535 An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web ap… Collaboration 10.0.8+ Fix from $1,9502024-08-12 HIGH 7.5 CVE-2024-7693 Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attack… Raidenmaild 5.0.2+ Fix from $1,9502024-08-12 CRITICAL 9.8 CVE-2024-7399 KEVEPSS 92% Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wr… Magicinfo 9 Server 21.1050.0+ Fix from $2,3002024-08-12 MEDIUM 5.3 CVE-2024-6759 When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This all… FreeBSD 13.0 / 13.3+ Fix from $1,6002024-08-12 CRITICAL 9.8 CVE-2024-42469 openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometV… Openhab 4.2.1+ Fix from $2,3002024-08-12 HIGH 7.5 CVE-2024-42468 openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions p… Openhab 4.2.1+ Fix from $1,9502024-08-12 HIGH 7.5 CVE-2024-41936 A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior… Var1200 H Firmware after 3.3.23.6.9 Fix from $1,9502024-08-12 CRITICAL 9.1 CVE-2024-21876 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly know… Iq Gateway Firmware 8.2.4225+ Fix from $2,3002024-08-12 MEDIUM 6.5 CVE-2024-21877 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly … Iq Gateway Firmware 8.2.4225+ Fix from $1,6002024-08-12 HIGH 8.8 CVE-2024-0113 NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a … Mlnx Os 3.10.4500 / 3.10.4504+ Fix from $1,9502024-08-12 HIGH 8.8 CVE-2024-6707 Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability. Open Webui No fix yet Fix from $1,9502024-08-07 HIGH 7.8 CVE-2024-7061 Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.… Verify 5.0.2+ Fix from $1,9502024-08-07 MEDIUM 5.5 CVE-2024-37403 Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, r… Docs\@work 2.26.0+ Fix from $1,6002024-08-07 MEDIUM 6.5 CVE-2024-7564 Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sens… Unified Secops Platform Mitigation only Fix from $1,6002024-08-06 CRITICAL 9.8 CVE-2024-39226EPSS 21% GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 HIGH 8.8 CVE-2024-5709 The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_nam… Page Builder 7.8+ Fix from $1,9502024-08-06 HIGH 7.5 CVE-2024-6781EPSS 62% Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. Calibre after 7.14.0 Fix from $1,9502024-08-06 HIGH 8.8 CVE-2024-23657 Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on t… Nuxt 1.3.9+ Fix from $1,9502024-08-05 CRITICAL 9.8 CVE-2024-7458 A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/… Eladmin after 2.7 Fix from $2,3002024-08-04 HIGH 7.5 CVE-2024-41310 AndServer 2.1.12 is vulnerable to Directory Traversal. Andserver after 2.1.12 Fix from $1,9502024-08-02 MEDIUM 6.5 CVE-2024-7323 Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote att… Easyflow .net 6.6.17+ Fix from $1,6002024-08-02 MEDIUM 6.5 CVE-2024-38878EPSS 11% A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 … Omnivise T3000 Application Server Mitigation only Fix from $1,6002024-08-02 HIGH 7.2 CVE-2024-39621 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP … Listingpro 2.9.5+ Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-39624 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local F… Listingpro 2.9.5+ Fix from $1,9502024-08-01 MEDIUM 6.5 CVE-2024-38772 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce a… Mitigation only Fix from $1,6002024-08-01 CRITICAL 9.8 CVE-2024-39619 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP … Listingpro 2.9.5+ Fix from $2,3002024-08-01 HIGH 7.1 CVE-2024-38746 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories)… Mitigation only Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-38768 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local F… The Pack Elementor Addons 2.0.8.7+ Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-7340 The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse … Patch available Fix from $1,9502024-07-31 HIGH 7.8 CVE-2024-37129 Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially … Inventory Collector 12.3.0.6+ Fix from $1,9502024-07-31