Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2022-0902EPSS 17% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma… Rmc 100 Firmware 2105298-024 / 2105457-037+ Fix from $2,3002022-07-21 HIGH 7.5 CVE-2022-29834 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97… Genesis64 Mitigation only Fix from $1,9502022-07-20 HIGH 8.8 CVE-2022-1264 The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code. Ignition 8.1.10+ Fix from $1,9502022-07-20 HIGH 7.5 CVE-2022-24659 Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve ar… Goldshell Miner Firmware after 2.2.1 Fix from $1,9502022-07-20 MEDIUM 6.7 CVE-2022-30301 A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to del… Fortiap U after 6.2.3 Fix from $1,6002022-07-19 HIGH 8.1 CVE-2022-30302 Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 throu… Fortideceptor after 3.3.2 Fix from $1,9502022-07-19 MEDIUM 6.5 CVE-2022-2030 A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of … Usg Flex 100w Firmware after 5.30 Fix from $1,6002022-07-19 HIGH 7.8 CVE-2021-41031 A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a… Forticlient after 7.0.2 Fix from $1,9502022-07-18 MEDIUM 6.5 CVE-2022-31202 The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl. Softguard Web 5.1.5+ Fix from $1,6002022-07-17 HIGH 7.8 CVE-2022-35861 pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a… Pyenv after 2.3.2 Fix from $1,9502022-07-17 MEDIUM 6.5 CVE-2022-31159 The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists within the `downloadDirectory` m… Aws Sdk Java after 1.12.260 Fix from $1,6002022-07-15 CRITICAL 9.8 CVE-2022-32409EPSS 13% A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to … I3geo No fix yet Fix from $2,3002022-07-14 HIGH 7.5 CVE-2022-34762 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware … Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 HIGH 7.8 CVE-2022-20220 In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of priv… Android Patch available Fix from $1,9502022-07-13 CRITICAL 9.3 CVE-2022-31576 The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used … Shackerpanel after 2021-05-25 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31577 The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is us… Audio Aligner App after 2020-01-10 Fix from $2,3002022-07-11 HIGH 7.5 CVE-2022-31578 The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Bt Lnmp after 2019-10-10 Fix from $1,9502022-07-11 CRITICAL 9.3 CVE-2022-31579 The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Iasset after 2022-05-04 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31580 The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used … Caretakerr Api after 2021-05-17 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31581 The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Openmf 2022-05-03+ Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31582 The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Videoserver after 2019-09-21 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31583 The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function i… Automatedquizeval after 2020-04-27 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31584 The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. S3label after 2019-08-14 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31585 The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used… Home Internet after 2020-08-28 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31586 The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function i… Changepop Back after 2019-06-04 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31587 The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is use… Kg Fashion Chatbot after 2018-05-22 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31588 The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Testplatform after 2016-07-19 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31550 The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafel… Python Athena Stack after 2019-11-08 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31551 The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used un… Flask Mongo Skel after 2012-11-01 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31552 The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is use… Anuvaad Corpus after 2020-11-23 Fix from $2,3002022-07-11