Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2024-25154 Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to retur… Filecatalyst Direct 3.8.9+ Fix from $1,6002024-03-13 CRITICAL 9.9 CVE-2024-27317EPSS 57% In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu… Pulsar 2.10.6 / 2.11.4+ Fix from $2,3002024-03-12 CRITICAL 9.0 CVE-2024-21400 Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability Confidental Containers 0.3.3+ Fix from $2,3002024-03-12 MEDIUM 6.5 CVE-2024-1303 Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vu… Monitool 4.7+ Fix from $1,6002024-03-12 MEDIUM 6.5 CVE-2024-27279 Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x se… A Blog Cms after 3.1.9 Fix from $1,6002024-03-12 HIGH 7.2 CVE-2024-27121 Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the … Mitigation only Fix from $1,9502024-03-12 HIGH 7.5 CVE-2024-2318 A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of … Zkbio Media Mitigation only Fix from $1,9502024-03-08 HIGH 7.1 CVE-2024-23216 A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. … macOS 12.7.4 / 13.6.5+ Fix from $1,9502024-03-08 CRITICAL 9.1 CVE-2024-0818 Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6 Paddlepaddle 2.6.0+ Fix from $2,3002024-03-07 CRITICAL 9.8 CVE-2024-28222 In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenti… Netbackup 3.1.2 / 8.1.2+ Fix from $2,3002024-03-07 HIGH 7.5 CVE-2024-27765 Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateControlle… Jeewms after 3.7 Fix from $1,9502024-03-05 CRITICAL 9.8 CVE-2024-27764 An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component. Jeewms after 3.7 Fix from $2,3002024-03-05 CRITICAL 9.1 CVE-2024-25614 There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to… Arubaos 8.10.0.10 / 8.11.2.1+ Fix from $2,3002024-03-05 HIGH 7.5 CVE-2024-25164 iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionali… Idurar No fix yet Fix from $1,9502024-03-05 HIGH 7.3 CVE-2024-27199 KEVEPSS 100% In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible Teamcity 2023.11.4+ Fix from $1,9502024-03-04 HIGH 8.1 CVE-2024-28088 LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call.… Langchain 0.1.12+ Fix from $1,9502024-03-04 HIGH 7.5 CVE-2024-24307 Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attack… Product Designer 1.178.36+ Fix from $1,9502024-03-03 HIGH 8.8 CVE-2024-25386 Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code… Mitigation only Fix from $1,9502024-03-01 MEDIUM 5.3 CVE-2023-38366 IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacke… Filenet Content Manager Mitigation only Fix from $1,6002024-03-01 MEDIUM 5.5 CVE-2024-2045 Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possi… Session No fix yet Fix from $1,6002024-03-01 CRITICAL 9.8 CVE-2024-25830EPSS 24% F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker… Datacube3 Firmware No fix yet Fix from $2,3002024-02-29 HIGH 8.1 CVE-2024-25006 XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZI… Xenforo 2.2.14+ Fix from $1,9502024-02-29 CRITICAL 9.1 CVE-2024-25065EPSS 48% Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $2,3002024-02-29 MEDIUM 5.3 CVE-2024-23946 Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $1,6002024-02-29 HIGH 7.1 CVE-2024-25859 A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbi… Blesta 5.9.2+ Fix from $1,9502024-02-28 HIGH 8.1 CVE-2024-0763 Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would … Anythingllm 1.0.0+ Fix from $1,9502024-02-27 HIGH 7.5 CVE-2024-25711 diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclos… Fedora 256+ Fix from $1,9502024-02-27 HIGH 8.8 CVE-2024-27081 ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHo… Esphome Patch available Fix from $1,9502024-02-26 HIGH 8.8 CVE-2024-1886 This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage. Webos Signage Mitigation only Fix from $1,9502024-02-26 MEDIUM 6.5 CVE-2024-1165 The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This ma… Brizy 2.4.40+ Fix from $1,6002024-02-26