Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2024-22523 Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage … Ifair after 23.8_ad0 Fix from $1,9502024-01-30 HIGH 7.5 CVE-2024-23334EPSS 77% aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it … Fedora 3.9.2+ Fix from $1,9502024-01-29 MEDIUM 6.5 CVE-2023-30970 Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on … Gotham Blackbird Witchcraft 1.1.0 / 103.30230304.433+ Fix from $1,6002024-01-29 CRITICAL 9.8 CVE-2024-23822 Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form … Thruk 3.12+ Fix from $2,3002024-01-29 CRITICAL 9.8 CVE-2024-23827 Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does n… Nginx Ui Mitigation only Fix from $2,3002024-01-29 CRITICAL 9.8 CVE-2024-0989 A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the fu… Kuerp after 1.0.4 Fix from $2,3002024-01-29 CRITICAL 9.9 CVE-2024-0402 An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which a… GitLab 16.5.8 / 16.6.6+ Fix from $2,3002024-01-26 MEDIUM 6.5 CVE-2023-41474EPSS 38% Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.… Avalanche No fix yet Fix from $1,6002024-01-25 HIGH 7.5 CVE-2024-0882 A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-… Linkwechat No fix yet Fix from $1,9502024-01-25 HIGH 7.8 CVE-2023-52076 Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerabili… Atril 1.26.2+ Fix from $1,9502024-01-25 CRITICAL 9.8 CVE-2024-23897 KEVEPSS 100% Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a … Jenkins 2.426.3 / 2.442+ Fix from $2,3002024-01-24 MEDIUM 6.5 CVE-2024-23899 Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed b… Git Server after 99.va_0826a_b_cdfa_d Fix from $1,6002024-01-24 HIGH 7.5 CVE-2024-23904 Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path … Log Command after 1.0.2 Fix from $1,9502024-01-24 MEDIUM 5.3 CVE-2024-22204 Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in… Whoogle Search 0.8.4+ Fix from $1,6002024-01-23 HIGH 8.1 CVE-2024-23182 Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.… A Blog Cms 2.10.50 / 2.11.58+ Fix from $1,9502024-01-23 MEDIUM 5.3 CVE-2024-23340 @hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request objec… Node Server 1.4.1+ Fix from $1,6002024-01-22 HIGH 7.8 CVE-2022-45792 Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overw… Sysmac Studio 1.54.0+ Fix from $1,9502024-01-22 MEDIUM 6.5 CVE-2023-44395 Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path trav… Autolab 2.12.0+ Fix from $1,6002024-01-22 HIGH 8.8 CVE-2024-23768 Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folde… Dremio 22.2.3 / 23.2.4+ Fix from $1,9502024-01-22 CRITICAL 9.8 CVE-2024-0769 KEVEPSS 83% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some un… Dir 859 Firmware Mitigation only Fix from $2,3002024-01-21 MEDIUM 5.3 CVE-2023-35020 IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL… Sterling Control Center Patch available Fix from $1,6002024-01-19 CRITICAL 9.8 CVE-2024-22415 jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve… Language Server Protocol Integration 2.2.2+ Fix from $2,3002024-01-18 MEDIUM 5.5 CVE-2023-5097 Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7. Workforce Access 8.7+ Fix from $1,6002024-01-16 HIGH 8.8 CVE-2021-24566 The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode. Fox Currency Switcher Professional For Woocommerce 1.3.7+ Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2023-6623EPSS 51% The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templat… Essential Blocks 4.4.3+ Fix from $2,3002024-01-15 MEDIUM 6.5 CVE-2023-46749 Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe… Shiro 1.13.0+ Fix from $1,6002024-01-15 HIGH 7.5 CVE-2023-48383 NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can e… Airpass Mitigation only Fix from $1,9502024-01-15 HIGH 7.5 CVE-2023-52288 An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to … Flaskcode after 0.0.8 Fix from $1,9502024-01-13 HIGH 7.5 CVE-2023-52289 An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to… Flaskcode after 0.0.8 Fix from $1,9502024-01-13 HIGH 7.5 CVE-2023-48166 A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to vie… Openscape Voice Mitigation only Fix from $1,9502024-01-12