Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2023-40266 An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal. Unify Openscape Xpressions Webassistant 7r1_fr5_hf42_p911+ Fix from $2,3002024-02-08 HIGH 7.5 CVE-2024-24311 Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6… Multilingual And Multistore Sitemap Pro 1.6.6+ Fix from $1,9502024-02-07 MEDIUM 5.0 CVE-2024-0849 Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR. Desktop Mitigation only Fix from $1,6002024-02-07 HIGH 8.8 CVE-2024-22514 An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file. Agent Dvr Mitigation only Fix from $1,9502024-02-06 HIGH 8.8 CVE-2024-24591 A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset … Clearml after 1.14.1 Fix from $1,9502024-02-06 MEDIUM 5.3 CVE-2024-24942EPSS 32% In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives Teamcity 2023.11.3+ Fix from $1,6002024-02-06 MEDIUM 5.3 CVE-2024-24938 In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation Teamcity 2023.11.2+ Fix from $1,6002024-02-06 HIGH 7.5 CVE-2024-23673 Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli… Sling Servlets Resolver 2.11.0+ Fix from $1,9502024-02-06 CRITICAL 9.8 CVE-2024-24398 Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via… Dashboards.php 2024.1.2+ Fix from $2,3002024-02-06 CRITICAL 9.4 CVE-2024-0964 A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request. Gradio Patch available Fix from $2,3002024-02-05 HIGH 7.2 CVE-2024-0221 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… Photo Gallery 1.8.20+ Fix from $1,9502024-02-05 CRITICAL 9.8 CVE-2023-6989EPSS 57% The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions u… Shield Security 18.5.10+ Fix from $2,3002024-02-05 CRITICAL 9.6 CVE-2023-52138 Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged t… Engrampa 1.26.2+ Fix from $2,3002024-02-05 MEDIUM 5.3 CVE-2023-7216 A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a… Enterprise Linux No fix yet Fix from $1,6002024-02-05 CRITICAL 9.8 CVE-2023-7077 Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705,… Nec E705 Firmware Mitigation only Fix from $2,3002024-02-05 HIGH 7.2 CVE-2021-46902 An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validati… Lantime Firmware 6.24.029 / 7.04.008+ Fix from $1,9502024-02-04 HIGH 7.2 CVE-2024-0844 The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChan… Ai Popup 2.2.5+ Fix from $1,9502024-02-02 HIGH 7.5 CVE-2023-39611 An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted w… Chart Fx No fix yet Fix from $1,9502024-02-02 HIGH 7.5 CVE-2024-22851 Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the … Liveconfig 2.5.2+ Fix from $1,9502024-02-02 HIGH 7.5 CVE-2021-22281 : Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation S… Automation Studio after 4.12 Fix from $1,9502024-02-02 CRITICAL 9.8 CVE-2024-24482 Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal. Apktool 2.9.3+ Fix from $2,3002024-02-02 MEDIUM 6.5 CVE-2023-38019 IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially … Soar Qradar Plugin App 5.0.3+ Fix from $1,6002024-02-02 CRITICAL 9.8 CVE-2024-22779 Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerP… Serverrpexposer after 1.0.2 Fix from $2,3002024-02-02 MEDIUM 6.5 CVE-2024-22096 In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a sp… Rapid Scada after 5.8.4 Fix from $1,6002024-02-02 HIGH 7.5 CVE-2024-24756 Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested f… Crafatar 2.1.5+ Fix from $1,9502024-02-01 HIGH 8.8 CVE-2024-21852 In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vu… Rapid Scada after 5.8.4 Fix from $1,9502024-02-01 CRITICAL 9.1 CVE-2024-23652 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend … Buildkit 0.12.5+ Fix from $2,3002024-01-31 MEDIUM 5.3 CVE-2023-5390 An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlE… Controledge Unit Operations Controller Firmware Mitigation only Fix from $1,6002024-01-31 CRITICAL 9.8 CVE-2024-24579 stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an O… Stereoscope 0.0.1+ Fix from $2,3002024-01-31 MEDIUM 6.5 CVE-2024-24565 CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function i… Cratedb 5.3.9 / 5.4.8+ Fix from $1,6002024-01-30