Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-40742
Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitra…
Mail Sqr Expert
Mitigation only
MEDIUM 6.5
CVE-2022-39367
QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine allows users to upload QTI con…
Qtiworks
1.0+
MEDIUM 6.5
CVE-2022-26884
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
Dolphinscheduler
2.0.6+
HIGH 7.5
CVE-2021-38399
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauth…
C200 Firmware
Mitigation only
MEDIUM 5.3
CVE-2022-3387EPSS 14%
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could remotely exploit vulnerable PHP…
R Seenet
after 2.4.19
MEDIUM 5.8
CVE-2022-0072
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This …
Openlitespeed
1.7.16.1+
HIGH 7.1
CVE-2022-20954
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…
Telepresence Collaboration Endpoint
10.19.1+
HIGH 7.1
CVE-2022-20955
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…
Telepresence Collaboration Endpoint
10.19.1+
MEDIUM 6.7
CVE-2022-20776
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…
Telepresence Collaboration Endpoint
10.20.1+
HIGH 7.2
CVE-2022-20811
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…
Telepresence Collaboration Endpoint
9.15.13.0 / 10.15.1+
HIGH 8.1
CVE-2022-20822
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read a…
Identity Services Engine
Mitigation only
MEDIUM 5.5
CVE-2022-20953
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path…
Telepresence Collaboration Endpoint
10.19.1+
HIGH 7.5
CVE-2022-43748
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation management in Synology Presto File Ser…
Presto File Server
2.1.2-1601+
HIGH 7.5
CVE-2022-39345
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5…
Gin Vue Admin
2.5.4+
HIGH 8.1
CVE-2022-38196
Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service by allowing a remote, authent…
Arcgis Server
after 10.9.1
CRITICAL 9.1
CVE-2022-33897
A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted network reques…
R1510 Firmware
No fix yet
MEDIUM 5.5
CVE-2022-41780
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the …
F5os A
1.1.0 / 1.4.0+
HIGH 7.5
CVE-2022-42188
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Lavalite
No fix yet
HIGH 7.5
CVE-2022-39058
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass …
Rava Certificate Validation System
Mitigation only
HIGH 7.3
CVE-2022-3060
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to gene…
GitLab
after 12.7.0
CRITICAL 9.8
CVE-2022-22128
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow rem…
Tableau Server
after 2022.1.4
CRITICAL 9.8
CVE-2022-23770
This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remot…
Smart Wing Cms
19051+
HIGH 7.2
CVE-2022-38421EPSS 79%
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…
Coldfusion
Patch available
HIGH 7.5
CVE-2022-38422EPSS 44%
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…
Coldfusion
Mitigation only
HIGH 7.2
CVE-2022-38424EPSS 45%
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2022-38418EPSS 80%
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Dir…
Coldfusion
Patch available
HIGH 7.5
CVE-2021-22685
An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.
Access Controller
2.0.1+
HIGH 7.5
CVE-2021-20030
SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing applicat…
Global Management System
9.3.2+
HIGH 7.1
CVE-2022-33937
Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privileged attacker could potential…
Geodrive
2.2.3+
HIGH 7.5
CVE-2022-39802EPSS 7%
SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The …
Manufacturing Execution
No fix yet