Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2022-2531 An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all… GitLab 15.0.5 / 15.1.4+ Fix from $1,6002022-08-05 HIGH 7.5 CVE-2022-31662 VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with netw… Identity Manager Patch available Fix from $1,9502022-08-05 MEDIUM 5.5 CVE-2021-27798 A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric O… Fabric Operating System Mitigation only Fix from $1,6002022-08-05 HIGH 7.5 CVE-2022-31793EPSS 16% do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before … Muhttpd 1.1.7+ Fix from $1,9502022-08-04 HIGH 7.7 CVE-2022-31473 In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attacker may be able to bypass App… Big Ip Access Policy Manager 15.1.4+ Fix from $1,9502022-08-04 MEDIUM 6.5 CVE-2022-2653 With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environ… Planka 1.5.1+ Fix from $1,6002022-08-04 HIGH 7.5 CVE-2022-32963 OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pa… Omicard Edm after 6.0 Fix from $1,9502022-08-04 HIGH 7.5 CVE-2022-35216 OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-p… Omicard Edm after 6.0 Fix from $1,9502022-08-04 MEDIUM 6.5 CVE-2022-27618 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before … Storage Analyzer 2.0.1-0214 / 2.1.0-0390+ Fix from $1,6002022-08-03 MEDIUM 6.5 CVE-2022-30572 The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploitable Directory Traversal vul… Iway Service Manager 8.0.7+ Fix from $1,6002022-08-02 MEDIUM 6.5 CVE-2022-35918 Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable t… Streamlit 1.11.1+ Fix from $1,6002022-08-01 HIGH 7.5 CVE-2022-35920 Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using e… Sanic 20.12.7 / 21.12.2+ Fix from $1,9502022-08-01 HIGH 7.2 CVE-2022-31194 DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace… Dspace 6.4+ Fix from $1,9502022-08-01 HIGH 7.2 CVE-2022-31195 DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServic… Dspace 6.4+ Fix from $1,9502022-08-01 HIGH 8.8 CVE-2022-2184 The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abu… Captcha 4wp 7.1.0+ Fix from $1,9502022-08-01 CRITICAL 9.8 CVE-2021-22650 An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to cod… Twinsoft 1.46 / 12.4+ Fix from $2,3002022-07-28 HIGH 8.1 CVE-2022-27611 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5… Audio Station 6.5.4-3367+ Fix from $1,9502022-07-28 HIGH 8.1 CVE-2022-22685 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4… Webdav Server 2.4.0-0062+ Fix from $1,9502022-07-28 HIGH 8.1 CVE-2022-27615 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-502… Dns Server 2.2.2-5027+ Fix from $1,9502022-07-28 MEDIUM 6.5 CVE-2021-46830 A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerabi… Goanywhere Managed File Transfer 6.8.3+ Fix from $1,6002022-07-27 HIGH 8.8 CVE-2022-36889 Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployme… Deployer Framework after 85.v1d1888e8c021 Fix from $1,9502022-07-27 MEDIUM 6.5 CVE-2022-34551 Sims v1.0 was discovered to allow path traversal when downloading attachments. Sims No fix yet Fix from $1,6002022-07-27 HIGH 8.1 CVE-2022-27610 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM… Diskstation Manager 6.2.3-25423+ Fix from $1,9502022-07-27 HIGH 7.2 CVE-2022-1648 Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intend… Pandora Fms after 7.0_ng_760 Fix from $1,9502022-07-26 HIGH 7.5 CVE-2022-24992 A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal. Qr Code Generator after 5.2.7 Fix from $1,9502022-07-25 HIGH 7.5 CVE-2022-35650EPSS 49% The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in… Moodle 3.9.15 / 3.11.8+ Fix from $1,9502022-07-25 CRITICAL 9.8 CVE-2017-20145 A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The att… Responsive Filemanager after 9.11.0 Fix from $2,3002022-07-25 MEDIUM 6.5 CVE-2022-1128 Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to … Chrome 100.0.4896.60+ Fix from $1,6002022-07-23 CRITICAL 9.8 CVE-2022-2139EPSS 15% The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. Iview 5.7.04.6469+ Fix from $2,3002022-07-22 HIGH 8.1 CVE-2022-31163 TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as … Debian Linux 0.3.61 / 1.2.10+ Fix from $1,9502022-07-22