Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2022-31514
The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used uns…
Fan Platform
after 2021-04-20
CRITICAL 9.3
CVE-2022-31515
The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Carceresbe
No fix yet
CRITICAL 9.3
CVE-2022-31516
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Harveyzyh Python
after 2022-05-04
CRITICAL 9.3
CVE-2022-31517
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Mercury Sample Manager
after 2021-04-20
CRITICAL 9.3
CVE-2022-31518
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send…
Python Recipe Database
after 2021-03-31
CRITICAL 9.3
CVE-2022-31519
The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Windmill
No fix yet
CRITICAL 9.3
CVE-2022-31520
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is us…
Logstash Management Api
after 2020-05-04
CRITICAL 9.3
CVE-2022-31521
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Mosaic
No fix yet
CRITICAL 9.3
CVE-2022-31522
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Karaokey
after 2019-12-11
CRITICAL 9.3
CVE-2022-31523
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Anakin
after 0.1.1
CRITICAL 9.3
CVE-2022-31524
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used un…
Pure Swagger
after 1.1.5
HIGH 7.5
CVE-2022-35410
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect…
Debian Linux
0.13.0+
CRITICAL 9.8
CVE-2022-25046EPSS 56%
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
Webpanel
after 0.9.8.1124
MEDIUM 6.5
CVE-2022-20791
A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Ma…
Unified Communications Manager
14su2+
MEDIUM 6.5
CVE-2022-20812
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication S…
Expressway
Mitigation only
CRITICAL 9.8
CVE-2022-31836
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
Beego
after 2.0.3
HIGH 7.5
CVE-2022-32551
Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).
Manageengine Servicedesk Plus Msp
10.6+
CRITICAL 9.1
CVE-2022-28127EPSS 35%
A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request …
R1510 Firmware
No fix yet
HIGH 8.1
CVE-2017-20105
A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the arg…
Simplessus
No fix yet
MEDIUM 6.5
CVE-2022-33116
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to re…
Openeclass
after 3.12.4
MEDIUM 5.5
CVE-2017-20102
A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. T…
Album Lock
Mitigation only
CRITICAL 9.1
CVE-2022-1953
The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, acc…
Product Configurator For Woocommerce
1.2.32+
CRITICAL 9.8
CVE-2022-2119
OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files i…
Dcmtk
3.6.7+
CRITICAL 9.8
CVE-2022-2120
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM fi…
Dcmtk
3.6.7+
CRITICAL 9.1
CVE-2022-30117
Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrar…
Concrete Cms
8.5.8 / 9.1.0+
CRITICAL 9.8
CVE-2022-1518
LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure.
Local Run Manager
after 3.1
MEDIUM 6.5
CVE-2013-1891EPSS 6%
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Opencart
after 1.5.5.1
MEDIUM 6.5
CVE-2021-41636
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating…
Ftp Server
No fix yet
HIGH 7.5
CVE-2022-34177
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the …
Pipeline\
after 448.v37cea_9a_10a_70
HIGH 7.5
CVE-2022-34179
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image sty…
Embeddable Build Status
after 2.0.3