Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-31395
Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent …
8373 Ip Zone Paging Adapter Firmware
No fix yet
HIGH 7.5
CVE-2022-33995
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an a…
Remote Desktop Manager
2022.2+
CRITICAL 9.8
CVE-2022-29774EPSS 6%
iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
Ispy
No fix yet
MEDIUM 5.3
CVE-2022-31062EPSS 6%
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.…
Glpi Inventory
1.0.2+
HIGH 7.5
CVE-2022-25856
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read()…
Argo Events
1.7.1+
HIGH 7.5
CVE-2022-31372
Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a …
Mathtype
Patch available
HIGH 8.8
CVE-2021-33036
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…
Hadoop
2.10.2 / 3.2.3+
CRITICAL 9.1
CVE-2022-32328
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.
Fast Food Ordering System
No fix yet
HIGH 7.5
CVE-2022-29509
Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier,…
T\&d Server
after 2.30
HIGH 8.8
CVE-2022-1657
Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Pat…
Jupiter
after 6.10.1
MEDIUM 6.5
CVE-2022-26041
Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter …
Rccmd
after 4.26
HIGH 7.1
CVE-2022-29093
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) …
Supportassist For Business Pcs
after 3.10.4
HIGH 7.1
CVE-2022-29094
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) …
Supportassist For Business Pcs
after 3.10.4
CRITICAL 9.8
CVE-2022-24278
The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerabili…
Convert Svg
0.6.4+
MEDIUM 6.5
CVE-2021-42811
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to rea…
Safenet Keysecure
after 8.12.4
CRITICAL 9.1
CVE-2022-1992
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
Gogs
0.12.9+
HIGH 8.1
CVE-2022-1993EPSS 52%
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
Gogs
0.12.9+
HIGH 8.1
CVE-2021-40668
The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directo…
Http File Server
No fix yet
CRITICAL 9.8
CVE-2022-24840
django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 …
Django S3file
5.5.1+
MEDIUM 6.5
CVE-2022-0779
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low …
User Meta User Profile Builder And User Management
2.4.4+
MEDIUM 6.5
CVE-2022-28478
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sani…
Seeddms
Patch available
HIGH 7.5
CVE-2022-32275EPSS 9%
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd …
Grafana
No fix yet
HIGH 8.8
CVE-2022-31483
An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the …
Lp1501 Firmware
1.271+
CRITICAL 9.8
CVE-2022-32270
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code …
Realplayer
No fix yet
MEDIUM 6.5
CVE-2022-29597
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to refe…
Regulatory Reporting System
No fix yet
MEDIUM 6.5
CVE-2022-30804
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
Elite Cms
No fix yet
CRITICAL 9.8
CVE-2022-28945
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
Webcube
Mitigation only
HIGH 7.5
CVE-2022-1661EPSS 16%
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.
N6854a Firmware
2.4.0+
HIGH 7.5
CVE-2022-23082
In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which ma…
Curekit
after 1.1.3
MEDIUM 6.5
CVE-2022-30508
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
Dedecms
No fix yet