Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-23470
Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, wh…
Galaxy
after 22.05
HIGH 7.5
CVE-2022-2969
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d…
Dialink
1.5.0.0+
HIGH 7.8
CVE-2022-29837
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to ini…
My Cloud Home Firmware
8.12.0-178+
HIGH 8.1
CVE-2022-4030
The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be man…
Simple\
after 6.8.0
HIGH 7.5
CVE-2022-25848
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the pa…
Static Dev Server
No fix yet
HIGH 8.8
CVE-2022-44635EPSS 69%
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Ap…
Fineract
1.8.1+
HIGH 7.5
CVE-2022-45921
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker m…
Fusionauth
1.41.3+
CRITICAL 9.8
CVE-2022-41158
Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploi…
Eyoom Builder
after 4.5.3
MEDIUM 6.5
CVE-2022-41712
Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc…
Frappe
No fix yet
HIGH 7.5
CVE-2022-40977
A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious …
Pasvisu
1.6.102 / 1.12.0+
MEDIUM 5.5
CVE-2022-40976
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuratio…
Pas 4000
1.4.0 / 1.4.1+
HIGH 7.0
CVE-2022-44749
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files …
Knime Analytics Platform
4.6.4+
HIGH 7.5
CVE-2022-44748
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritte…
Knime Server
4.13.6 / 4.14.3+
MEDIUM 5.3
CVE-2022-45866
qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../…
Fedora
11.3+
MEDIUM 6.5
CVE-2022-44280
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.
Automotive Shop Management System
No fix yet
HIGH 7.8
CVE-2022-4065
A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function …
Testng
Patch available
CRITICAL 9.8
CVE-2022-41840EPSS 5%
Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.
Welcart E Commerce
2.7.8+
CRITICAL 9.8
CVE-2022-38165
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary loca…
F Secure Policy Manager
Mitigation only
MEDIUM 5.3
CVE-2022-39178
Webvendome - webvendome Internal Server IP Disclosure.
Send GET Request to the request which is shown in the picture.
Internal Server IP and Full pat…
Webvendome
Mitigation only
MEDIUM 5.3
CVE-2022-3090
Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are …
Crimson
3.0+
HIGH 8.8
CVE-2022-41920
Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package…
Lancet
1.3.4 / 2.1.10+
MEDIUM 5.3
CVE-2022-42892
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an ope…
Syngo Dynamics Cardiovascular Imaging And Information System
Mitigation only
CRITICAL 9.8
CVE-2022-44006
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, un…
Backclick
No fix yet
MEDIUM 6.5
CVE-2022-44008
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-en…
Backclick
No fix yet
MEDIUM 5.7
CVE-2022-39347
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for…
Fedora
2.9.0+
HIGH 7.5
CVE-2022-43264
Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted…
Guitar Pro
1.10.2+
HIGH 7.5
CVE-2020-12508
In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the image-relocator m…
Moni\
4.2+
HIGH 7.5
CVE-2022-45388
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers…
Config Rotator
after 2.0.1
HIGH 8.1
CVE-2022-45381
Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Com…
Pipeline Utility Steps
2.13.2+
HIGH 7.5
CVE-2022-42123
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before…
Digital Experience Platform
7.4.3.19+