Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-0902EPSS 17%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma…
Rmc 100 Firmware
2105298-024 / 2105457-037+
HIGH 7.5
CVE-2022-29834
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97…
Genesis64
Mitigation only
HIGH 8.8
CVE-2022-1264
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.
Ignition
8.1.10+
HIGH 7.5
CVE-2022-24659
Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve ar…
Goldshell Miner Firmware
after 2.2.1
MEDIUM 6.7
CVE-2022-30301
A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to del…
Fortiap U
after 6.2.3
HIGH 8.1
CVE-2022-30302
Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 throu…
Fortideceptor
after 3.3.2
MEDIUM 6.5
CVE-2022-2030
A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of …
Usg Flex 100w Firmware
after 5.30
HIGH 7.8
CVE-2021-41031
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a…
Forticlient
after 7.0.2
MEDIUM 6.5
CVE-2022-31202
The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.
Softguard Web
5.1.5+
HIGH 7.8
CVE-2022-35861
pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a…
Pyenv
after 2.3.2
MEDIUM 6.5
CVE-2022-31159
The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` m…
Aws Sdk Java
after 1.12.260
CRITICAL 9.8
CVE-2022-32409EPSS 13%
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to …
I3geo
No fix yet
HIGH 7.5
CVE-2022-34762
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware …
Opc Ua Module For M580 Firmware
after 1.10
HIGH 7.8
CVE-2022-20220
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv…
Android
Patch available
CRITICAL 9.3
CVE-2022-31576
The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used …
Shackerpanel
after 2021-05-25
CRITICAL 9.3
CVE-2022-31577
The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is us…
Audio Aligner App
after 2020-01-10
HIGH 7.5
CVE-2022-31578
The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Bt Lnmp
after 2019-10-10
CRITICAL 9.3
CVE-2022-31579
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Iasset
after 2022-05-04
CRITICAL 9.3
CVE-2022-31580
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used …
Caretakerr Api
after 2021-05-17
CRITICAL 9.3
CVE-2022-31581
The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Openmf
2022-05-03+
CRITICAL 9.3
CVE-2022-31582
The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Videoserver
after 2019-09-21
CRITICAL 9.3
CVE-2022-31583
The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function i…
Automatedquizeval
after 2020-04-27
CRITICAL 9.3
CVE-2022-31584
The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
S3label
after 2019-08-14
CRITICAL 9.3
CVE-2022-31585
The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used…
Home Internet
after 2020-08-28
CRITICAL 9.3
CVE-2022-31586
The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function i…
Changepop Back
after 2019-06-04
CRITICAL 9.3
CVE-2022-31587
The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is use…
Kg Fashion Chatbot
after 2018-05-22
CRITICAL 9.3
CVE-2022-31588
The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Testplatform
after 2016-07-19
CRITICAL 9.3
CVE-2022-31550
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafel…
Python Athena Stack
after 2019-11-08
CRITICAL 9.3
CVE-2022-31551
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used un…
Flask Mongo Skel
after 2012-11-01
CRITICAL 9.3
CVE-2022-31552
The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is use…
Anuvaad Corpus
after 2020-11-23