Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2024-31487 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSan… Fortisandbox 4.2.7 / 4.4.5+ Fix from $1,6002024-04-09 MEDIUM 6.7 CVE-2023-47541 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSa… Fortisandbox 4.2.7 / 4.4.3+ Fix from $1,6002024-04-09 CRITICAL 9.8 CVE-2024-2224 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone… Endpoint Security Mitigation only Fix from $2,3002024-04-09 MEDIUM 6.5 CVE-2024-31860 Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files… Zeppelin 0.11.0+ Fix from $1,6002024-04-09 HIGH 7.6 CVE-2024-31978 A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users to export monitoring data. The… Mitigation only Fix from $1,9502024-04-09 HIGH 7.5 CVE-2024-30417 Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confiden… Emui Mitigation only Fix from $1,9502024-04-07 HIGH 7.8 CVE-2024-0406 A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a… Advanced Cluster Security 4.0.0 / 4.18.4+ Fix from $1,9502024-04-06 HIGH 7.5 CVE-2024-22328 IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially cr… Maximo Application Suite Mitigation only Fix from $1,9502024-04-06 CRITICAL 9.8 CVE-2024-31848EPSS 8% A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could a… Mitigation only Fix from $2,3002024-04-05 CRITICAL 9.8 CVE-2024-31849EPSS 6% A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allo… Mitigation only Fix from $2,3002024-04-05 HIGH 8.6 CVE-2024-31850 A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an… Mitigation only Fix from $1,9502024-04-05 HIGH 8.6 CVE-2024-31851 A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow a… Mitigation only Fix from $1,9502024-04-05 HIGH 7.3 CVE-2024-31220 Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely… Sunshine 0.18.0+ Fix from $1,9502024-04-05 HIGH 8.8 CVE-2024-29672 Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC… Patch available Fix from $1,9502024-04-05 MEDIUM 6.2 CVE-2024-30270EPSS 27% mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versio… Mailcow\ 2024-04+ Fix from $1,6002024-04-04 HIGH 8.8 CVE-2024-3311 A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability is the function ZipUtils.unZ… Dreamer Cms 4.1.3.1+ Fix from $1,9502024-04-04 MEDIUM 5.8 CVE-2024-30254 MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1.4 allows overwriting arbitra… Patch available Fix from $1,6002024-04-04 CRITICAL 9.9 CVE-2024-25693 There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse… Portal For Arcgis after 11.2 Fix from $2,3002024-04-04 HIGH 7.5 CVE-2024-27575 INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as with the /… Mitigation only Fix from $1,9502024-04-04 MEDIUM 5.3 CVE-2024-23540 The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory serve… Mitigation only Fix from $1,6002024-04-03 HIGH 7.5 CVE-2024-20348 A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated… Nexus Dashboard Fabric Controller Mitigation only Fix from $1,9502024-04-03 HIGH 8.8 CVE-2024-20352 A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow… Emergency Responder 12.5+ Fix from $1,9502024-04-03 MEDIUM 5.3 CVE-2023-35812 An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within t… Mitigation only Fix from $1,6002024-04-03 HIGH 8.3 CVE-2024-29434 An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file. Alldata Mitigation only Fix from $1,9502024-04-02 MEDIUM 6.5 CVE-2016-15038 A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.p… No fix yet Fix from $1,6002024-04-01 HIGH 7.5 CVE-2024-25944 Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit t… Openmanage Enterprise 4.0.1+ Fix from $1,9502024-03-29 CRITICAL 9.8 CVE-2024-3078 A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/co… Qdrant 1.8.3+ Fix from $2,3002024-03-29 HIGH 7.5 CVE-2021-31156 Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data. Mitigation only Fix from $1,9502024-03-28 MEDIUM 6.5 CVE-2023-25341 A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user… Mitigation only Fix from $1,6002024-03-28 HIGH 8.6 CVE-2023-42947 A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS… Ipados 10.2 / 12.7.2+ Fix from $1,9502024-03-28