Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.1 CVE-2024-0980 The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code. No fix yet Fix from $1,9502024-03-28 CRITICAL 9.8 CVE-2023-0582 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypa… Access Management 7.1.4+ Fix from $2,3002024-03-27 CRITICAL 9.1 CVE-2024-28335 Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory,… Patch available Fix from $2,3002024-03-27 HIGH 8.8 CVE-2024-2203 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clie… The Plus Addons For Elementor 5.4.2+ Fix from $1,9502024-03-27 MEDIUM 6.4 CVE-2024-2210 The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team… The Plus Addons For Elementor 5.4.2+ Fix from $1,6002024-03-27 HIGH 7.5 CVE-2024-25136 There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the co… Mitigation only Fix from $1,9502024-03-26 MEDIUM 5.5 CVE-2023-52623 In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning whi… Linux Kernel 4.19.307 / 5.4.269+ Fix from $1,6002024-03-26 HIGH 7.8 CVE-2023-41973 ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName … Client Connector 4.3.0.121+ Fix from $1,9502024-03-26 CRITICAL 9.8 CVE-2024-2863EPSS 64% This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant. Lg Led Assistant Mitigation only Fix from $2,3002024-03-25 HIGH 7.5 CVE-2024-2227 This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (… Identityiq 8.1+ Fix from $1,9502024-03-22 HIGH 8.8 CVE-2024-25567 Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that … Diaenergie 1.10.00.005+ Fix from $1,9502024-03-21 HIGH 8.1 CVE-2024-28171 It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the… Diaenergie 1.10.00.005+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-27921EPSS 61% Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior … Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 7.5 CVE-2024-29180 Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address s… Webpack Dev Middleware 5.3.4 / 6.1.2+ Fix from $1,9502024-03-21 MEDIUM 5.4 CVE-2024-1142 Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted requ… Mitigation only Fix from $1,6002024-03-21 HIGH 7.5 CVE-2024-23721 A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the fu… Vigor3910 Firmware after 4.3.2.5 Fix from $1,9502024-03-20 HIGH 7.2 CVE-2023-41877 GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in ve… Geoserver after 2.23.4 Fix from $1,9502024-03-20 HIGH 8.8 CVE-2024-21677 This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a… Confluence Data Center 7.19.20 / 8.5.7+ Fix from $1,9502024-03-19 HIGH 7.5 CVE-2023-40279 An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main… Openclinic Ga No fix yet Fix from $1,9502024-03-19 HIGH 8.8 CVE-2024-24042 Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirect in Ru… Patch available Fix from $1,9502024-03-19 MEDIUM 5.5 CVE-2024-24043 Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file. Patch available Fix from $1,6002024-03-19 HIGH 7.5 CVE-2023-40280 An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popu… Openclinic Ga No fix yet Fix from $1,9502024-03-19 CRITICAL 9.8 CVE-2024-27768 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE Unilogic 1.35.227+ Fix from $2,3002024-03-18 HIGH 8.8 CVE-2024-27770 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal Unilogic 1.35.227+ Fix from $1,9502024-03-18 HIGH 8.8 CVE-2024-27771 Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE Unilogic 1.35.227+ Fix from $1,9502024-03-18 HIGH 7.5 CVE-2023-40747 Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. If this v… Mitigation only Fix from $1,9502024-03-18 MEDIUM 6.5 CVE-2024-25156 A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th… Goanywhere Managed File Transfer 7.4.2+ Fix from $1,6002024-03-14 HIGH 8.5 CVE-2024-27102 Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability … Wings 1.11.9+ Fix from $1,9502024-03-13 MEDIUM 6.5 CVE-2024-1358 The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render f… Elementor Addon Elements 1.13+ Fix from $1,6002024-03-13 CRITICAL 9.9 CVE-2023-6825EPSS 6% The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (fre… File Manager after 8.3.4 Fix from $2,3002024-03-13