Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.1 CVE-2024-1132 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali… Build Of Keycloak 22.0.10 / 24.0.3+ Fix from $1,9502024-04-17 MEDIUM 5.3 CVE-2024-32023 Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `find_and_replace` functio… Kohya Ss 24.0.1+ Fix from $1,6002024-04-16 MEDIUM 6.5 CVE-2024-32024 Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `add_pre_postfix` function… Kohya Ss 24.0.1+ Fix from $1,6002024-04-16 MEDIUM 5.3 CVE-2024-31451 DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixe… Patch available Fix from $1,6002024-04-16 HIGH 8.8 CVE-2024-3571 langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its L… Langchain Patch available Fix from $1,9502024-04-16 CRITICAL 9.3 CVE-2024-3573 mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary fil… Mlflow 2.10.0+ Fix from $2,3002024-04-16 HIGH 8.8 CVE-2024-1961 vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. A… Mitigation only Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-1593 A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequenc… Mlflow 2.11.3+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-1594 A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when cre… Mlflow 2.11.3+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-1483 A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a serie… Mlflow 2.12.1+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-1558 A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to i… Mlflow 2.12.1+ Fix from $1,9502024-04-16 HIGH 8.1 CVE-2024-1560 A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass … Mlflow after 2.9.2 Fix from $1,9502024-04-16 MEDIUM 6.5 CVE-2024-3783 The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files… Wbsairback Mitigation only Fix from $1,6002024-04-15 MEDIUM 5.5 CVE-2023-52144 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Prod… Mitigation only Fix from $1,6002024-04-15 CRITICAL 9.8 CVE-2024-3737 A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery o… Nginxwebui 4.2.4+ Fix from $2,3002024-04-13 MEDIUM 6.3 CVE-2024-31462 stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a lim… Patch available Fix from $1,6002024-04-12 HIGH 8.2 CVE-2024-32005 NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource file… Patch available Fix from $1,9502024-04-12 HIGH 7.5 CVE-2024-3686 A vulnerability has been found in DedeCMS 5.7.112-UTF8 and classified as problematic. Affected by this vulnerability is an unknown functionality of t… Dedecms No fix yet Fix from $1,9502024-04-12 CRITICAL 9.8 CVE-2024-31818 Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php compon… Derbynet No fix yet Fix from $2,3002024-04-12 MEDIUM 6.5 CVE-2024-29502 An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths. Secure Lockdown No fix yet Fix from $1,6002024-04-10 CRITICAL 9.8 CVE-2024-2221 qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint… Qdrant Patch available Fix from $2,3002024-04-10 HIGH 7.5 CVE-2024-1728EPSS 85% gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton compone… Gradio 4.19.2+ Fix from $1,9502024-04-10 CRITICAL 9.8 CVE-2024-1511 The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This … Lollms Web Ui No fix yet Fix from $2,3002024-04-10 MEDIUM 6.5 CVE-2024-31287 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects … Media Library Folders 8.1.9+ Fix from $1,6002024-04-10 HIGH 8.1 CVE-2024-31240 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Ma… Wp Poll Maker 3.4+ Fix from $1,9502024-04-10 MEDIUM 6.8 CVE-2024-2654 The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup fun… File Manager 7.2.6+ Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-1974 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via… Ht Mega 2.4.7+ Fix from $1,6002024-04-09 HIGH 7.7 CVE-2024-31457 gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversio… Patch available Fix from $1,9502024-04-09 HIGH 8.8 CVE-2024-29053 Microsoft Defender for IoT Remote Code Execution Vulnerability Defender For Iot 24.1.3+ Fix from $1,9502024-04-09 HIGH 8.1 CVE-2024-23671 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSan… Fortisandbox 4.0.5 / 4.2.7+ Fix from $1,9502024-04-09