Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2022-2531
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all…
GitLab
15.0.5 / 15.1.4+
HIGH 7.5
CVE-2022-31662
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with netw…
Identity Manager
Patch available
MEDIUM 5.5
CVE-2021-27798
A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric O…
Fabric Operating System
Mitigation only
HIGH 7.5
CVE-2022-31793EPSS 16%
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before …
Muhttpd
1.1.7+
HIGH 7.7
CVE-2022-31473
In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attacker may be able to bypass App…
Big Ip Access Policy Manager
15.1.4+
MEDIUM 6.5
CVE-2022-2653
With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environ…
Planka
1.5.1+
HIGH 7.5
CVE-2022-32963
OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pa…
Omicard Edm
after 6.0
HIGH 7.5
CVE-2022-35216
OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-p…
Omicard Edm
after 6.0
MEDIUM 6.5
CVE-2022-27618
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before …
Storage Analyzer
2.0.1-0214 / 2.1.0-0390+
MEDIUM 6.5
CVE-2022-30572
The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vul…
Iway Service Manager
8.0.7+
MEDIUM 6.5
CVE-2022-35918
Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable t…
Streamlit
1.11.1+
HIGH 7.5
CVE-2022-35920
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using e…
Sanic
20.12.7 / 21.12.2+
HIGH 7.2
CVE-2022-31194
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace…
Dspace
6.4+
HIGH 7.2
CVE-2022-31195
DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServic…
Dspace
6.4+
HIGH 8.8
CVE-2022-2184
The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abu…
Captcha 4wp
7.1.0+
CRITICAL 9.8
CVE-2021-22650
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to cod…
Twinsoft
1.46 / 12.4+
HIGH 8.1
CVE-2022-27611
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5…
Audio Station
6.5.4-3367+
HIGH 8.1
CVE-2022-22685
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4…
Webdav Server
2.4.0-0062+
HIGH 8.1
CVE-2022-27615
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-502…
Dns Server
2.2.2-5027+
MEDIUM 6.5
CVE-2021-46830
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerabi…
Goanywhere Managed File Transfer
6.8.3+
HIGH 8.8
CVE-2022-36889
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployme…
Deployer Framework
after 85.v1d1888e8c021
MEDIUM 6.5
CVE-2022-34551
Sims v1.0 was discovered to allow path traversal when downloading attachments.
Sims
No fix yet
HIGH 8.1
CVE-2022-27610
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM…
Diskstation Manager
6.2.3-25423+
HIGH 7.2
CVE-2022-1648
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intend…
Pandora Fms
after 7.0_ng_760
HIGH 7.5
CVE-2022-24992
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
Qr Code Generator
after 5.2.7
HIGH 7.5
CVE-2022-35650EPSS 49%
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in…
Moodle
3.9.15 / 3.11.8+
CRITICAL 9.8
CVE-2017-20145
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The att…
Responsive Filemanager
after 9.11.0
MEDIUM 6.5
CVE-2022-1128
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to …
Chrome
100.0.4896.60+
CRITICAL 9.8
CVE-2022-2139EPSS 15%
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.
Iview
5.7.04.6469+
HIGH 8.1
CVE-2022-31163
TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as …
Debian Linux
0.3.61 / 1.2.10+