Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2022-4511 A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the compo… Docsys No fix yet Fix from $1,9502022-12-15 MEDIUM 5.3 CVE-2020-24855 Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request. Easywebpack Cli 4.5.2+ Fix from $1,6002022-12-15 MEDIUM 6.5 CVE-2022-29511 A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A spe… Lansweeper No fix yet Fix from $1,6002022-12-15 HIGH 8.8 CVE-2022-29517EPSS 58% A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-craf… Lansweeper No fix yet Fix from $1,9502022-12-15 HIGH 8.8 CVE-2022-32573 A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP … Lansweeper No fix yet Fix from $1,9502022-12-15 MEDIUM 6.5 CVE-2022-27498EPSS 38% A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A… Lansweeper Mitigation only Fix from $1,6002022-12-15 HIGH 7.5 CVE-2022-31703 The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system… Vrealize Log Insight after 8.10.1 Fix from $1,9502022-12-14 CRITICAL 9.8 CVE-2022-46255 An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code exec… Enterprise Server Mitigation only Fix from $2,3002022-12-14 HIGH 8.8 CVE-2022-46256 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To ex… Enterprise Server 3.3.17 / 3.4.12+ Fix from $1,9502022-12-14 HIGH 8.1 CVE-2022-23512 MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::de… Metersphere 2.4.1+ Fix from $1,9502022-12-14 CRITICAL 9.8 CVE-2022-4493 A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUnpackResource of the file src/… Scifio 2022-07-29+ Fix from $2,3002022-12-14 CRITICAL 9.8 CVE-2022-4494 A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is the function extractZip of th… Mcp Mapping Viewer 2022-09-22+ Fix from $2,3002022-12-14 HIGH 8.8 CVE-2022-34271 A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas ver… Atlas after 2.2.0 Fix from $1,9502022-12-14 HIGH 7.1 CVE-2022-40264 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versions 10.96 … Genesis64 after 10.97.2 Fix from $1,9502022-12-14 HIGH 7.8 CVE-2022-29580 There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symb… Google Search 13.41+ Fix from $1,9502022-12-13 HIGH 7.5 CVE-2022-45269 A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files. Linx Sphere No fix yet Fix from $1,9502022-12-12 MEDIUM 6.5 CVE-2022-44532 An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vuln… Edgeconnect Enterprise after 9.2.1.0 Fix from $1,6002022-12-12 HIGH 7.8 CVE-2022-44653 A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privile… Apex One 14.0.11789+ Fix from $1,9502022-12-12 MEDIUM 6.5 CVE-2022-43518 An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability… Edgeconnect Enterprise after 9.2.1.0 Fix from $1,6002022-12-12 HIGH 8.1 CVE-2022-37906 An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in t… Sd Wan 6.5.4.22 / 8.6.0.17+ Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-4402 A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompressio… Docsys after 2.02.37 Fix from $1,9502022-12-11 CRITICAL 9.1 CVE-2022-45290 Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java. Kbase Doc No fix yet Fix from $2,3002022-12-09 MEDIUM 5.5 CVE-2022-46826 In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. Intellij Idea 2022.3+ Fix from $1,6002022-12-08 HIGH 7.5 CVE-2022-41720 On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files roo… Go 1.18.9 / 1.19.4+ Fix from $1,9502022-12-07 MEDIUM 5.3 CVE-2020-36565 Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files out… Echo 4.2.0+ Fix from $1,6002022-12-07 HIGH 8.1 CVE-2022-44942 Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. Casdoor 1.126.1+ Fix from $1,9502022-12-07 HIGH 8.1 CVE-2022-45829 Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. Easy Wp Smtp after 1.5.1 Fix from $1,9502022-12-06 MEDIUM 6.5 CVE-2022-45833 Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. Easy Wp Smtp after 1.5.1 Fix from $1,6002022-12-06 CRITICAL 9.1 CVE-2022-44900 A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to wri… Py7zr 0.20.1+ Fix from $2,3002022-12-06 HIGH 7.5 CVE-2022-46154 Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users … Kodexplorer 4.50+ Fix from $1,9502022-12-06