Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2022-39296 MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affec… Melis Asset Manager 5.0.1+ Fix from $1,9502022-10-11 HIGH 7.5 CVE-2022-34430 Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability… Hybrid Client 1.8+ Fix from $1,9502022-10-11 HIGH 8.8 CVE-2022-34426 Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which cou… Container Storage Modules 2.0.0+ Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-39858 Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamer… Factorycamera 3.5.51+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-3389 Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. Rdiffweb 2.4.10+ Fix from $1,9502022-10-06 HIGH 7.1 CVE-2022-42308 An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by le… Netbackup after 8.2 Fix from $1,9502022-10-03 HIGH 7.5 CVE-2022-42305 An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path trav… Netbackup after 10.0.0.1 Fix from $1,9502022-10-03 MEDIUM 6.5 CVE-2022-40123 mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability all… Mojoportal No fix yet Fix from $1,6002022-10-03 HIGH 7.1 CVE-2022-34429 Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability… Hybrid Client Mitigation only Fix from $1,9502022-09-30 HIGH 7.1 CVE-2022-20850 A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to dele… Sd Wan Vbond Orchestrator 16.10.1 / 18.4.5+ Fix from $1,9502022-09-30 HIGH 7.8 CVE-2022-20775 KEVEPSS 12% A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability i… Catalyst Sd Wan Manager 20.6.3 / 20.7.2+ Fix from $1,9502022-09-30 HIGH 7.8 CVE-2022-20818 Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerab… Sd Wan Vbond Orchestrator 20.9+ Fix from $1,9502022-09-30 HIGH 8.1 CVE-2021-33354 Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter. Htmly 2.8.1+ Fix from $1,9502022-09-30 CRITICAL 9.8 CVE-2022-28814 Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulne… Cpy Car Park Server 2.8.3 / 8.5.0.3+ Fix from $2,3002022-09-28 HIGH 7.5 CVE-2022-39261 Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem… Twig 1.44.7 / 2.15.3+ Fix from $1,9502022-09-28 HIGH 7.5 CVE-2022-40082 Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. Hertz Patch available Fix from $1,9502022-09-28 CRITICAL 9.8 CVE-2022-39033 Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL paramete… Smart Evision Mitigation only Fix from $2,3002022-09-28 MEDIUM 6.5 CVE-2022-39034 Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote at… Smart Evision Mitigation only Fix from $1,6002022-09-28 CRITICAL 9.8 CVE-2022-41352 KEVEPSS 95% An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extr… Zimbra Collaboration Suite Patch available Fix from $2,3002022-09-26 HIGH 7.5 CVE-2022-34026 ICEcoder v8.1 allows attackers to execute a directory traversal. Icecoder No fix yet Fix from $1,9502022-09-22 MEDIUM 5.3 CVE-2022-40443 An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/sitein… Zzcms No fix yet Fix from $1,6002022-09-22 MEDIUM 5.3 CVE-2022-40444 ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server. Zzcms No fix yet Fix from $1,6002022-09-22 HIGH 7.5 CVE-2022-28981 Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside… Liferay Portal after 7.4.2 Fix from $1,9502022-09-22 MEDIUM 5.5 CVE-2022-29799EPSS 12% A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeSt… Windows Defender For Endpoint Patch available Fix from $1,6002022-09-21 MEDIUM 5.7 CVE-2022-41231 Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenki… Build Publisher after 1.22 Fix from $1,6002022-09-21 HIGH 7.5 CVE-2022-2265 The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vuln… Identity And Directory Management System 2.1.25+ Fix from $1,9502022-09-21 HIGH 7.5 CVE-2022-39221 McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric … Mcwebserver Minecraft Mod For Fabric And Quilt after 0.1.2.1 Fix from $1,9502022-09-21 HIGH 7.2 CVE-2022-38340 Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload. Fme Server 2021.2.6 / 2022.0.1+ Fix from $1,9502022-09-20 CRITICAL 9.8 CVE-2022-23767 This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfe… Securegate after 3.5.5 Fix from $2,3002022-09-19 HIGH 7.5 CVE-2022-40608 IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating… Spectrum Protect Plus after 10.1.11 Fix from $1,9502022-09-19