Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2022-23470 Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, wh… Galaxy after 22.05 Fix from $1,9502022-12-06 HIGH 7.5 CVE-2022-2969 Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or d… Dialink 1.5.0.0+ Fix from $1,9502022-12-01 HIGH 7.8 CVE-2022-29837 A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to ini… My Cloud Home Firmware 8.12.0-178+ Fix from $1,9502022-12-01 HIGH 8.1 CVE-2022-4030 The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be man… Simple\ after 6.8.0 Fix from $1,9502022-11-29 HIGH 7.5 CVE-2022-25848 This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the pa… Static Dev Server No fix yet Fix from $1,9502022-11-29 HIGH 8.8 CVE-2022-44635EPSS 69% Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Ap… Fineract 1.8.1+ Fix from $1,9502022-11-29 HIGH 7.5 CVE-2022-45921 FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker m… Fusionauth 1.41.3+ Fix from $1,9502022-11-28 CRITICAL 9.8 CVE-2022-41158 Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploi… Eyoom Builder after 4.5.3 Fix from $2,3002022-11-25 MEDIUM 6.5 CVE-2022-41712 Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not correc… Frappe No fix yet Fix from $1,6002022-11-25 HIGH 7.5 CVE-2022-40977 A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious … Pasvisu 1.6.102 / 1.12.0+ Fix from $1,9502022-11-24 MEDIUM 5.5 CVE-2022-40976 A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuratio… Pas 4000 1.4.0 / 1.4.1+ Fix from $1,6002022-11-24 HIGH 7.0 CVE-2022-44749 A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above can result in arbitrary files … Knime Analytics Platform 4.6.4+ Fix from $1,9502022-11-24 HIGH 7.5 CVE-2022-44748 A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritte… Knime Server 4.13.6 / 4.14.3+ Fix from $1,9502022-11-24 MEDIUM 5.3 CVE-2022-45866 qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../… Fedora 11.3+ Fix from $1,6002022-11-23 MEDIUM 6.5 CVE-2022-44280 Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img. Automotive Shop Management System No fix yet Fix from $1,6002022-11-23 HIGH 7.8 CVE-2022-4065 A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function … Testng Patch available Fix from $1,9502022-11-19 CRITICAL 9.8 CVE-2022-41840EPSS 5% Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress. Welcart E Commerce 2.7.8+ Fix from $2,3002022-11-18 CRITICAL 9.8 CVE-2022-38165 Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary loca… F Secure Policy Manager Mitigation only Fix from $2,3002022-11-17 MEDIUM 5.3 CVE-2022-39178 Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. Internal Server IP and Full pat… Webvendome Mitigation only Fix from $1,6002022-11-17 MEDIUM 5.3 CVE-2022-3090 Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are … Crimson 3.0+ Fix from $1,6002022-11-17 HIGH 8.8 CVE-2022-41920 Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package… Lancet 1.3.4 / 2.1.10+ Fix from $1,9502022-11-17 MEDIUM 5.3 CVE-2022-42892 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an ope… Syngo Dynamics Cardiovascular Imaging And Information System Mitigation only Fix from $1,6002022-11-17 CRITICAL 9.8 CVE-2022-44006 An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, un… Backclick No fix yet Fix from $2,3002022-11-16 MEDIUM 6.5 CVE-2022-44008 An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-en… Backclick No fix yet Fix from $1,6002022-11-16 MEDIUM 5.7 CVE-2022-39347 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for… Fedora 2.9.0+ Fix from $1,6002022-11-16 HIGH 7.5 CVE-2022-43264 Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted… Guitar Pro 1.10.2+ Fix from $1,9502022-11-16 HIGH 7.5 CVE-2020-12508 In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the image-relocator m… Moni\ 4.2+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-45388 Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers… Config Rotator after 2.0.1 Fix from $1,9502022-11-15 HIGH 8.1 CVE-2022-45381 Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Com… Pipeline Utility Steps 2.13.2+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-42123 A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before… Digital Experience Platform 7.4.3.19+ Fix from $1,9502022-11-15