Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-34375
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user wi…
Container Storage Modules
1.3.0+
HIGH 7.5
CVE-2022-37681
Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traver…
Hc Ip9100hd Firmware
after 1.07
HIGH 7.2
CVE-2022-2261
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashb…
Wpide
3.0+
MEDIUM 6.5
CVE-2022-36687
Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=d…
Ingredient Stock Management System
No fix yet
HIGH 7.5
CVE-2022-38794
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
Zaver
after 2020-12-15
HIGH 8.1
CVE-2021-40285
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.
Htmly
Patch available
HIGH 7.8
CVE-2022-2463
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exc…
Isagraf Workbench
after 6.6.9
HIGH 7.8
CVE-2022-2464
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can…
Isagraf Workbench
after 6.6.9
HIGH 8.8
CVE-2022-32427
PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the drive…
Windows Client
25.0.0.688+
HIGH 8.2
CVE-2022-34836
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages an…
Zenon
after 8.20
CRITICAL 9.1
CVE-2022-36261
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?act…
Taocms
No fix yet
HIGH 7.2
CVE-2022-34486
Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a…
Pukiwiki
1.5.4+
CRITICAL 9.9
CVE-2022-30547EPSS 64%
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafte…
Avideo
No fix yet
HIGH 8.8
CVE-2022-2557
The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a pa…
Team Wordpress Team Members Showcase
4.1.2+
HIGH 7.3
CVE-2022-2788
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip att…
Electric\'s Proficy
after 9.80
HIGH 7.5
CVE-2022-37422
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.
Payara
4.1.2.191.36 / 5.42.0+
HIGH 7.5
CVE-2022-37060EPSS 18%
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An un…
Flir Ax8 Firmware
after 1.46.16
HIGH 7.2
CVE-2022-1373EPSS 13%
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing z…
Edgeaggregator
Mitigation only
HIGH 7.5
CVE-2021-42052
IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query…
E Flow
No fix yet
HIGH 8.8
CVE-2022-34254
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname t…
Commerce
2.3.7 / 2.4.3+
HIGH 7.5
CVE-2020-21365
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a …
Debian Linux
after 0.12.5
CRITICAL 9.8
CVE-2020-21642EPSS 7%
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attacke…
Manageengine Analytics Plus
Mitigation only
CRITICAL 9.8
CVE-2022-37042 KEVEPSS 92%
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing aut…
Zimbra Collaboration Suite
Patch available
HIGH 7.5
CVE-2022-37423
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
Awesome Procedures On Cypher
4.3.0.7 / 4.4.0.8+
CRITICAL 9.8
CVE-2022-38129EPSS 19%
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management…
Sensor Management Server
No fix yet
HIGH 7.5
CVE-2022-29804
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows po…
Go
1.17.11 / 1.18.3+
MEDIUM 6.5
CVE-2022-34365
WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read ac…
Wyse Management Suite
3.8.0+
HIGH 8.1
CVE-2022-20816
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager S…
Unified Communications Manager
14su2+
MEDIUM 5.5
CVE-2022-36831
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permiss…
Notes
4.3.14.39+
MEDIUM 5.5
CVE-2022-33715
Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of …
Android
Mitigation only