Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-49960 In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to… Profinet Inspektor Nt Firmware after 2.4.0 Fix from $1,9502024-02-26 HIGH 7.5 CVE-2024-27318 Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can hav… Fedora 1.16.0+ Fix from $1,9502024-02-23 HIGH 7.5 CVE-2024-26150 `@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backs… Backstage Backend Common 0.19.10 / 0.20.2+ Fix from $1,9502024-02-23 MEDIUM 6.5 CVE-2023-24416 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects Al… All In One Favicon 4.8+ Fix from $1,6002024-02-23 HIGH 7.5 CVE-2022-25377 The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory tr… Appwrite 0.12.2+ Fix from $1,9502024-02-22 HIGH 7.5 CVE-2024-25461 Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a cr… Crm Creatio Mitigation only Fix from $1,9502024-02-21 HIGH 8.1 CVE-2024-1704 A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the … Crmeb No fix yet Fix from $1,9502024-02-21 MEDIUM 5.3 CVE-2024-1703 A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /admina… Crmeb No fix yet Fix from $1,6002024-02-21 HIGH 8.4 CVE-2024-1708 KEVEPSS 88% ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote … Screenconnect 23.9.8+ Fix from $1,9502024-02-21 HIGH 8.8 CVE-2023-42791 A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 t… Fortimanager 6.2.12 / 6.4.13+ Fix from $1,9502024-02-20 HIGH 8.8 CVE-2024-21891 Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined im… Node.js 20.11.1 / 21.6.2+ Fix from $1,9502024-02-20 MEDIUM 5.3 CVE-2024-26129 PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure i… Prestashop 8.1.4+ Fix from $1,6002024-02-19 MEDIUM 6.5 CVE-2023-49508 Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensiti… Yetiforce Customer Relationship Management 6.5.0+ Fix from $1,6002024-02-16 HIGH 7.5 CVE-2024-25123 MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method tha… Mission Support System 8.3.3+ Fix from $1,9502024-02-15 CRITICAL 9.6 CVE-2024-23479EPSS 6% SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this v… Access Rights Manager 2023.2.3+ Fix from $2,3002024-02-15 CRITICAL 9.6 CVE-2024-23476EPSS 7% The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, th… Access Rights Manager 2023.2.3+ Fix from $2,3002024-02-15 CRITICAL 9.6 CVE-2024-23477EPSS 8% The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, th… Access Rights Manager 2023.2.3+ Fix from $2,3002024-02-15 CRITICAL 9.8 CVE-2024-26261 The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put fi… Oaklouds Organization 2.0 188 / 1051+ Fix from $2,3002024-02-15 MEDIUM 6.4 CVE-2024-25620 Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a … Helm 3.14.1+ Fix from $1,6002024-02-15 MEDIUM 5.5 CVE-2024-23607 A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView director… F5os A 1.4.0 / 1.6.0+ Fix from $1,6002024-02-14 HIGH 8.0 CVE-2023-5123 The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that… Json Api Data Source 1.3.21+ Fix from $1,9502024-02-14 HIGH 7.8 CVE-2023-35003 Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privile… Virtual Raid On Cpu 8.0.8.1001+ Fix from $1,9502024-02-14 MEDIUM 6.5 CVE-2024-23787 Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent … Jh Rvb1 Firmware Mitigation only Fix from $1,6002024-02-14 MEDIUM 5.3 CVE-2024-25125EPSS 30% Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag w… Digdag 0.10.5.1+ Fix from $1,6002024-02-14 CRITICAL 9.3 CVE-2024-1485 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i… Openshift 0.0.0-20240206+ Fix from $2,3002024-02-14 MEDIUM 6.5 CVE-2024-1082 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by d… Enterprise Server 3.8.15 / 3.9.10+ Fix from $1,6002024-02-13 HIGH 7.1 CVE-2024-1163 The attacker may exploit a path traversal vulnerability leading to information disclosure. Mapshaper 0.6.44+ Fix from $1,9502024-02-13 HIGH 7.5 CVE-2024-23833 OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=… Openrefine 3.7.8+ Fix from $1,9502024-02-12 MEDIUM 6.5 CVE-2024-22226 Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potential… Unity Operating Environment 5.4.0.0.5.094+ Fix from $1,6002024-02-12 HIGH 7.2 CVE-2023-6294 The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the adminis… Popup Builder 4.2.6+ Fix from $1,9502024-02-12