Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2022-42125 Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers t… Digital Experience Platform 7.4.3.36+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-42977 The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export i… Confluence Data Center 1.3.5+ Fix from $1,9502022-11-15 HIGH 7.2 CVE-2022-45184 The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which al… Powershell Universal 3.4.7 / 3.5.3+ Fix from $1,9502022-11-14 HIGH 8.8 CVE-2022-3976 A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file… Libiec61850 1.5+ Fix from $1,9502022-11-13 HIGH 7.5 CVE-2022-3966 A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affects the function load_templat… Ultimate Member 2.5.1+ Fix from $1,9502022-11-13 HIGH 7.8 CVE-2022-36400 Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenti… Nuc Kit Wireless Adapter Driver Installer 22.40.0+ Fix from $1,9502022-11-11 CRITICAL 9.8 CVE-2022-3940 A vulnerability, which was classified as problematic, was found in lanyulei ferry. This affects an unknown part of the file apis/process/task.go. The… Ferry Mitigation only Fix from $2,3002022-11-11 CRITICAL 9.8 CVE-2022-3939 A vulnerability, which was classified as critical, has been found in lanyulei ferry. Affected by this issue is some unknown functionality of the file… Ferry Mitigation only Fix from $2,3002022-11-11 HIGH 7.5 CVE-2022-41607 All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory travers… Remote Access Server Firmware after 4.5.0 Fix from $1,9502022-11-10 HIGH 7.5 CVE-2022-39037 Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass … Agentflow Mitigation only Fix from $1,9502022-11-10 MEDIUM 6.5 CVE-2022-38120EPSS 6% UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authenticatio… Upsmon Pro Mitigation only Fix from $1,6002022-11-10 CRITICAL 9.8 CVE-2022-34822 Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServer… Expresscluster X after 5.0 Fix from $2,3002022-11-08 MEDIUM 5.5 CVE-2022-20453 In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local deni… Android Mitigation only Fix from $1,6002022-11-08 HIGH 7.5 CVE-2022-37866 When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include pla… Ivy 2.5.1+ Fix from $1,9502022-11-07 CRITICAL 9.1 CVE-2022-37865 With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip… Ivy 2.5.1+ Fix from $2,3002022-11-07 HIGH 7.2 CVE-2022-2711 The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing hig… Wp All Import 3.6.9+ Fix from $1,9502022-11-07 HIGH 7.5 CVE-2020-12509 In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the camera-file modul… Moni\ 4.2+ Fix from $1,9502022-11-07 HIGH 8.8 CVE-2022-20962 A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make una… Identity Services Engine Mitigation only Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41670 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41667 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 MEDIUM 6.5 CVE-2022-43451 OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arb… Openharmony after 3.1.2 Fix from $1,6002022-11-03 HIGH 7.5 CVE-2022-32287 A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files o… Uimaj after 3.3.0 Fix from $1,9502022-11-03 MEDIUM 6.5 CVE-2021-45448 Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates w… Vantara Pentaho 8.3.0.25 / 9.2.0.2+ Fix from $1,6002022-11-02 MEDIUM 5.3 CVE-2022-32938 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 16.1 and iPadOS 16, macOS … Ipados 13.0 / 16.0+ Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-34662 When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade… Dolphinscheduler 3.0.0+ Fix from $1,6002022-11-01 CRITICAL 9.8 CVE-2022-41657EPSS 21% Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in fil… Infrasuite Device Master 00.00.02a+ Fix from $2,3002022-10-31 CRITICAL 9.8 CVE-2022-41772EPSS 25% Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This pa… Infrasuite Device Master 00.00.02a+ Fix from $2,3002022-10-31 HIGH 7.5 CVE-2021-40661 A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing Terminals Build… Ind780 Firmware No fix yet Fix from $1,9502022-10-31 MEDIUM 6.5 CVE-2022-39022 U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to … U Office Force after 20.50.7821d Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-39023 U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to … U Office Force after 20.50.7821d Fix from $1,6002022-10-31