Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2022-40713 An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter,… 1350 Optical Management System Mitigation only Fix from $1,6002022-09-19 MEDIUM 6.5 CVE-2022-40715 An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, al… 1350 Optical Management System Mitigation only Fix from $1,6002022-09-19 HIGH 7.5 CVE-2022-37700 Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https:/… Zentao No fix yet Fix from $1,9502022-09-19 MEDIUM 5.5 CVE-2022-39210 Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not pr… Nextcloud 3.21.0+ Fix from $1,6002022-09-17 HIGH 7.5 CVE-2022-39001 The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. Emui No fix yet Fix from $1,9502022-09-16 MEDIUM 6.5 CVE-2022-34002 The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows… Pds Vista 7 7.1.7.2+ Fix from $1,6002022-09-16 MEDIUM 5.8 CVE-2022-39215 Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it … Tauri 1.0.6+ Fix from $1,6002022-09-15 MEDIUM 6.5 CVE-2022-1798 A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arb… Kubevirt 0.55.1+ Fix from $1,6002022-09-15 MEDIUM 6.5 CVE-2022-40734 UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as… Laravel Filemanager after 2.5.1 Fix from $1,6002022-09-14 HIGH 8.8 CVE-2022-38301 Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR … Onedev Patch available Fix from $1,9502022-09-14 HIGH 8.1 CVE-2022-36113 Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on… Cargo 0.65.0+ Fix from $1,9502022-09-14 HIGH 7.8 CVE-2022-20395 In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privile… Android Mitigation only Fix from $1,9502022-09-13 HIGH 7.5 CVE-2022-32190 JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the U… Go Patch available Fix from $1,9502022-09-13 HIGH 8.8 CVE-2022-26049 This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destinatio… Goomph 3.37.2+ Fix from $1,9502022-09-11 CRITICAL 9.1 CVE-2022-38638 Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. Casdoor Patch available Fix from $2,3002022-09-09 HIGH 7.5 CVE-2022-38614 An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifyi… Smartvista Cardgen No fix yet Fix from $1,9502022-09-09 MEDIUM 6.5 CVE-2022-38613 A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system. Smartvista Cardgen No fix yet Fix from $1,6002022-09-09 HIGH 8.1 CVE-2022-28741 aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing inpu… A\+hrd 5.4.1125v112 / 5.5.1098v156+ Fix from $1,9502022-09-09 MEDIUM 6.5 CVE-2022-37299 An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/co… Shirne Cms Patch available Fix from $1,6002022-09-09 HIGH 8.1 CVE-2022-38258 A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server inf… Dir 819 Firmware No fix yet Fix from $1,9502022-09-08 HIGH 7.5 CVE-2022-36081 Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when accessing `/list/<path:folderpath>`… Wikmd 1.7.1+ Fix from $1,9502022-09-07 HIGH 7.5 CVE-2022-36065 GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, att… Growthbook 1.6.0+ Fix from $1,9502022-09-06 MEDIUM 6.5 CVE-2022-29062 Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underly… Fortisoar 7.0.3+ Fix from $1,6002022-09-06 HIGH 8.6 CVE-2022-39838 Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to… Systematic Fix Adapter Firmware No fix yet Fix from $1,9502022-09-05 MEDIUM 5.5 CVE-2022-34378 Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. … Emc Powerscale Onefs after 9.4.0.3 Fix from $1,6002022-09-02 CRITICAL 9.8 CVE-2022-25371 Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in… Ofbiz 18.12.06+ Fix from $2,3002022-09-02 MEDIUM 6.5 CVE-2022-36593 kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java. Kkfileview No fix yet Fix from $1,6002022-09-02 HIGH 7.8 CVE-2022-34373 Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated mal… Command \| Integration Suite For System Center 6.2.0+ Fix from $1,9502022-08-31 HIGH 7.5 CVE-2022-37122EPSS 19% Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticate… Pcoweb Card Firmware No fix yet Fix from $1,9502022-08-31 HIGH 7.8 CVE-2022-36035 Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration… Flux2 0.32.0+ Fix from $1,9502022-08-31