Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.1 CVE-2020-36561 Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc… Unzip 1.0.3-0.20200308084313-2adbaa4891b9+ Fix from $2,3002022-12-27 CRITICAL 9.1 CVE-2020-36566 Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc… Tar Utils 0.0.0-20201201191210-20a61371de5b+ Fix from $2,3002022-12-27 HIGH 7.5 CVE-2019-25087 A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file… Httpserver 2019-09-08+ Fix from $1,9502022-12-27 CRITICAL 9.8 CVE-2022-4748 A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanag… Flatpress Patch available Fix from $2,3002022-12-27 MEDIUM 6.5 CVE-2021-39369 In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access fil… Myvue after 12.2.1.5 Fix from $1,6002022-12-26 CRITICAL 9.8 CVE-2020-36628 A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/cal… Android Processing Development Environment 0.5.2+ Fix from $2,3002022-12-25 HIGH 7.5 CVE-2020-36629 A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.c… Httpster 2020-11-19+ Fix from $1,9502022-12-25 MEDIUM 6.5 CVE-2022-45894 GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files. Planet Estream 6.72.10.07+ Fix from $1,6002022-12-25 HIGH 7.5 CVE-2022-44016 An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call… Lieferantenmanager 5.6+ Fix from $1,9502022-12-25 HIGH 7.5 CVE-2022-23854EPSS 46% AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with net… Intouch Access Anywhere 2020+ Fix from $1,9502022-12-23 CRITICAL 9.8 CVE-2022-47945EPSS 16% ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). … Thinkphp 6.0.14+ Fix from $2,3002022-12-23 HIGH 7.7 CVE-2022-46171 Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file pa… Tauri 1.0.8 / 1.1.3+ Fix from $1,9502022-12-23 MEDIUM 6.5 CVE-2022-46492 nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/get… Nbnbk No fix yet Fix from $1,6002022-12-23 CRITICAL 9.8 CVE-2022-3184EPSS 12% Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to a… Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $2,3002022-12-21 MEDIUM 6.5 CVE-2022-36221 Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the … Fastmile Firmware No fix yet Fix from $1,6002022-12-21 HIGH 7.5 CVE-2022-25895 All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the r… Lite Dev Server No fix yet Fix from $1,9502022-12-21 HIGH 7.5 CVE-2021-46856 The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiali… Emui Mitigation only Fix from $1,9502022-12-20 HIGH 7.5 CVE-2022-41591 The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files. Emui Mitigation only Fix from $1,9502022-12-20 HIGH 7.5 CVE-2022-25931 All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to th… Easy Static Server No fix yet Fix from $1,9502022-12-20 MEDIUM 6.8 CVE-2022-40607 IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directorie… Spectrum Scale after 5.1.4.0 Fix from $1,6002022-12-19 HIGH 7.2 CVE-2022-41418 An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary … Blogengine.net Patch available Fix from $1,9502022-12-19 CRITICAL 9.8 CVE-2022-4063EPSS 10% The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force th… Inpost Gallery 2.1.4.1+ Fix from $2,3002022-12-19 CRITICAL 9.8 CVE-2022-4594 A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the function deployWar of the file … Tjws2 2022-05-24+ Fix from $2,3002022-12-18 HIGH 8.8 CVE-2022-4583 A vulnerability was found in jLEMS. It has been declared as critical. Affected by this vulnerability is the function unpackJar of the file src/main/j… Jlems 2022-07-29+ Fix from $1,9502022-12-17 HIGH 7.1 CVE-2022-4572 A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue is the function ubireader_extr… Ubi Reader after 0.8.0 Fix from $1,9502022-12-17 HIGH 7.8 CVE-2022-23531 GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to 0.1.5 are vulnerable to Relative Path Traversal when scanning a special… Guarddog 0.1.5+ Fix from $1,9502022-12-17 MEDIUM 6.5 CVE-2022-23530 GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file write when scanning a specially… Guarddog 0.1.8+ Fix from $1,6002022-12-16 HIGH 7.5 CVE-2022-46137 AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1. Aerocms No fix yet Fix from $1,9502022-12-16 MEDIUM 6.7 CVE-2022-20505 In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv… Android Patch available Fix from $1,6002022-12-16 CRITICAL 9.8 CVE-2022-45969 Alist v3.4.0 is vulnerable to Directory Traversal, Alist Patch available Fix from $2,3002022-12-15