Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.3 CVE-2022-31514 The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used uns… Fan Platform after 2021-04-20 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31515 The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Carceresbe No fix yet Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31516 The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Harveyzyh Python after 2022-05-04 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31517 The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Mercury Sample Manager after 2021-04-20 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31518 The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send… Python Recipe Database after 2021-03-31 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31519 The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Windmill No fix yet Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31520 The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is us… Logstash Management Api after 2020-05-04 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31521 The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Mosaic No fix yet Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31522 The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Karaokey after 2019-12-11 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31523 The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. Anakin after 0.1.1 Fix from $2,3002022-07-11 CRITICAL 9.3 CVE-2022-31524 The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used un… Pure Swagger after 1.1.5 Fix from $2,3002022-07-11 HIGH 7.5 CVE-2022-35410 mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect… Debian Linux 0.13.0+ Fix from $1,9502022-07-08 CRITICAL 9.8 CVE-2022-25046EPSS 56% A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. Webpanel after 0.9.8.1124 Fix from $2,3002022-07-07 MEDIUM 6.5 CVE-2022-20791 A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Ma… Unified Communications Manager 14su2+ Fix from $1,6002022-07-06 MEDIUM 6.5 CVE-2022-20812 Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication S… Expressway Mitigation only Fix from $1,6002022-07-06 CRITICAL 9.8 CVE-2022-31836 The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk. Beego after 2.0.3 Fix from $2,3002022-07-05 HIGH 7.5 CVE-2022-32551 Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml). Manageengine Servicedesk Plus Msp 10.6+ Fix from $1,9502022-07-02 CRITICAL 9.1 CVE-2022-28127EPSS 35% A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request … R1510 Firmware No fix yet Fix from $2,3002022-06-30 HIGH 8.1 CVE-2017-20105 A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the arg… Simplessus No fix yet Fix from $1,9502022-06-28 MEDIUM 6.5 CVE-2022-33116 An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to re… Openeclass after 3.12.4 Fix from $1,6002022-06-27 MEDIUM 5.5 CVE-2017-20102 A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. T… Album Lock Mitigation only Fix from $1,6002022-06-27 CRITICAL 9.1 CVE-2022-1953 The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, acc… Product Configurator For Woocommerce 1.2.32+ Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-2119 OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files i… Dcmtk 3.6.7+ Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2022-2120 OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM fi… Dcmtk 3.6.7+ Fix from $2,3002022-06-24 CRITICAL 9.1 CVE-2022-30117 Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrar… Concrete Cms 8.5.8 / 9.1.0+ Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2022-1518 LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure. Local Run Manager after 3.1 Fix from $2,3002022-06-24 MEDIUM 6.5 CVE-2013-1891EPSS 6% In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. Opencart after 1.5.5.1 Fix from $1,6002022-06-24 MEDIUM 6.5 CVE-2021-41636 MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating… Ftp Server No fix yet Fix from $1,6002022-06-24 HIGH 7.5 CVE-2022-34177 Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the … Pipeline\ after 448.v37cea_9a_10a_70 Fix from $1,9502022-06-23 HIGH 7.5 CVE-2022-34179 Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image sty… Embeddable Build Status after 2.0.3 Fix from $1,9502022-06-23