Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2022-40742 Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitra… Mail Sqr Expert Mitigation only Fix from $1,6002022-10-31 MEDIUM 6.5 CVE-2022-39367 QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine allows users to upload QTI con… Qtiworks 1.0+ Fix from $1,6002022-10-28 MEDIUM 6.5 CVE-2022-26884 Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. Dolphinscheduler 2.0.6+ Fix from $1,6002022-10-28 HIGH 7.5 CVE-2021-38399 Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauth… C200 Firmware Mitigation only Fix from $1,9502022-10-28 MEDIUM 5.3 CVE-2022-3387EPSS 14% Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP… R Seenet after 2.4.19 Fix from $1,6002022-10-27 MEDIUM 5.8 CVE-2022-0072 Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This … Openlitespeed 1.7.16.1+ Fix from $1,6002022-10-27 HIGH 7.1 CVE-2022-20954 Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path… Telepresence Collaboration Endpoint 10.19.1+ Fix from $1,9502022-10-26 HIGH 7.1 CVE-2022-20955 Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path… Telepresence Collaboration Endpoint 10.19.1+ Fix from $1,9502022-10-26 MEDIUM 6.7 CVE-2022-20776 Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path… Telepresence Collaboration Endpoint 10.20.1+ Fix from $1,6002022-10-26 HIGH 7.2 CVE-2022-20811 Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path… Telepresence Collaboration Endpoint 9.15.13.0 / 10.15.1+ Fix from $1,9502022-10-26 HIGH 8.1 CVE-2022-20822 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read a… Identity Services Engine Mitigation only Fix from $1,9502022-10-26 MEDIUM 5.5 CVE-2022-20953 Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path… Telepresence Collaboration Endpoint 10.19.1+ Fix from $1,6002022-10-26 HIGH 7.5 CVE-2022-43748 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Ser… Presto File Server 2.1.2-1601+ Fix from $1,9502022-10-26 HIGH 7.5 CVE-2022-39345 Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5… Gin Vue Admin 2.5.4+ Fix from $1,9502022-10-25 HIGH 8.1 CVE-2022-38196 Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authent… Arcgis Server after 10.9.1 Fix from $1,9502022-10-25 CRITICAL 9.1 CVE-2022-33897 A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted network reques… R1510 Firmware No fix yet Fix from $2,3002022-10-25 MEDIUM 5.5 CVE-2022-41780 In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the … F5os A 1.1.0 / 1.4.0+ Fix from $1,6002022-10-19 HIGH 7.5 CVE-2022-42188 In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. Lavalite No fix yet Fix from $1,9502022-10-18 HIGH 7.5 CVE-2022-39058 RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass … Rava Certificate Validation System Mitigation only Fix from $1,9502022-10-18 HIGH 7.3 CVE-2022-3060 Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to gene… GitLab after 12.7.0 Fix from $1,9502022-10-17 CRITICAL 9.8 CVE-2022-22128 Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow rem… Tableau Server after 2022.1.4 Fix from $2,3002022-10-17 CRITICAL 9.8 CVE-2022-23770 This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remot… Smart Wing Cms 19051+ Fix from $2,3002022-10-17 HIGH 7.2 CVE-2022-38421EPSS 79% Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir… Coldfusion Patch available Fix from $1,9502022-10-14 HIGH 7.5 CVE-2022-38422EPSS 44% Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir… Coldfusion Mitigation only Fix from $1,9502022-10-14 HIGH 7.2 CVE-2022-38424EPSS 45% Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir… Coldfusion Mitigation only Fix from $1,9502022-10-14 CRITICAL 9.8 CVE-2022-38418EPSS 80% Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir… Coldfusion Patch available Fix from $2,3002022-10-14 HIGH 7.5 CVE-2021-22685 An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1. Access Controller 2.0.1+ Fix from $1,9502022-10-14 HIGH 7.5 CVE-2021-20030 SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing applicat… Global Management System 9.3.2+ Fix from $1,9502022-10-13 HIGH 7.1 CVE-2022-33937 Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potential… Geodrive 2.2.3+ Fix from $1,9502022-10-12 HIGH 7.5 CVE-2022-39802EPSS 7% SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The … Manufacturing Execution No fix yet Fix from $1,9502022-10-11