Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.5 CVE-2023-0592 A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to … Jefferson 0.4.1+ Fix from $1,6002023-01-31 MEDIUM 5.5 CVE-2023-0593 A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to w… Yaffshiv after 0.1 Fix from $1,6002023-01-31 HIGH 7.5 CVE-2022-39059 ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker c… Megaservisignadapter 1.0.22.1004+ Fix from $1,9502023-01-31 CRITICAL 9.8 CVE-2022-0223 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create … Ecostruxure Power Commission 2.22+ Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-22731 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attac… Ecostruxure Power Commission 2.22+ Fix from $2,3002023-01-30 HIGH 7.5 CVE-2022-38451 A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to … Freshtomato No fix yet Fix from $1,9502023-01-30 HIGH 7.5 CVE-2022-25936 Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable. Servst 2.0.3+ Fix from $1,9502023-01-30 HIGH 7.3 CVE-2022-48285 loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. Jszip 3.8.0+ Fix from $1,9502023-01-29 HIGH 7.5 CVE-2022-39812 Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to … Netmatch S Ci No fix yet Fix from $1,9502023-01-27 CRITICAL 9.8 CVE-2022-43979 There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha… Pandora Fms 766+ Fix from $2,3002023-01-27 HIGH 7.5 CVE-2019-25053 A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of … Sage Frp 1000 2019-11+ Fix from $1,9502023-01-27 HIGH 7.2 CVE-2021-41143 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute co… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 HIGH 7.5 CVE-2022-2712 In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting wi… Glassfish after 6.2.5 Fix from $1,9502023-01-27 MEDIUM 5.7 CVE-2022-47951 An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and … Debian Linux 20.0.2 / 23.0.1+ Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2022-41154 A directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafte… Quartz Gold Firmware No fix yet Fix from $1,6002023-01-26 HIGH 8.1 CVE-2022-40701 A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted … Quartz Gold Firmware No fix yet Fix from $1,9502023-01-26 HIGH 8.8 CVE-2022-39045 A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP reque… Quartz Gold Firmware No fix yet Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2022-38088 A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted… Quartz Gold Firmware No fix yet Fix from $1,6002023-01-26 HIGH 8.1 CVE-2023-24057 HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a cra… Hl7 Fhir Core 1.2.30 / 5.6.92+ Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-4510EPSS 22% A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyst… Binwalk 2.3.3+ Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-43864 IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craft… Business Automation Workflow after 21.0.3.1 Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2022-31706EPSS 87% The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system… Vrealize Log Insight 8.10.2+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-29844EPSS 36% A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read an… My Cloud Pr2100 Firmware 5.26.119+ Fix from $2,3002023-01-26 HIGH 7.5 CVE-2022-25882 Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to th… Onnx 1.13.0+ Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-21192 All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employ… Serve Lite No fix yet Fix from $1,9502023-01-26 CRITICAL 9.1 CVE-2020-18331 Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform G… Gpn2.4p21 C Cn Firmware No fix yet Fix from $2,3002023-01-26 CRITICAL 9.1 CVE-2020-18330 An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(… Gpn2.4p21 C Cn Firmware No fix yet Fix from $2,3002023-01-26 HIGH 7.5 CVE-2022-46639 A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal. Correos after 1.7.8 Fix from $1,9502023-01-23 HIGH 8.8 CVE-2023-23314 An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file. Zdir Patch available Fix from $1,9502023-01-23 HIGH 8.8 CVE-2023-22726 act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitiz… Act 0.2.40+ Fix from $1,9502023-01-20