Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
CRITICAL 9.8 CVE-2022-1664 Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa… Dpkg 1.18.26 / 1.19.8+ Fix from $2,3002022-05-26 HIGH 7.5 CVE-2022-30427 In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal. Ginadmin after 2022-05-10 Fix from $1,9502022-05-25 HIGH 8.6 CVE-2022-30321 go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed i… Go Getter after 1.5.11 Fix from $1,9502022-05-25 MEDIUM 5.3 CVE-2021-32964 The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary fil… Webserver after 4.0.40.1014 Fix from $1,6002022-05-24 HIGH 8.1 CVE-2022-1850 Path Traversal in GitHub repository filegator/filegator prior to 7.8.0. Filegator 7.8.0+ Fix from $1,9502022-05-24 HIGH 7.5 CVE-2022-31268EPSS 11% A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathna… Gitblit No fix yet Fix from $1,9502022-05-21 HIGH 7.5 CVE-2022-1359 The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside… Cnmaestro Mitigation only Fix from $1,9502022-05-17 MEDIUM 6.5 CVE-2022-29332 D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the r… Dir 825 Firmware No fix yet Fix from $1,6002022-05-17 HIGH 8.8 CVE-2021-42643 cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website… Cmseasy No fix yet Fix from $1,9502022-05-17 MEDIUM 6.5 CVE-2022-1560 The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Loc… Amministrazione Aperta 3.8+ Fix from $1,6002022-05-16 HIGH 7.5 CVE-2022-1721 Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application. Drawio 18.0.5+ Fix from $1,9502022-05-16 CRITICAL 9.8 CVE-2022-24830 OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vul… Openclinica 3.13.1 / 3.16.2+ Fix from $2,3002022-05-14 HIGH 7.5 CVE-2021-33005 mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories. Mypro 8.20.0+ Fix from $1,9502022-05-13 CRITICAL 9.1 CVE-2022-25591 BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web serv… Blogengine.net No fix yet Fix from $2,3002022-05-13 HIGH 7.6 CVE-2021-27771 User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m… Sametime Mitigation only Fix from $1,9502022-05-12 CRITICAL 9.8 CVE-2022-23166 Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" … Sysaid 22.1.64 / 22.2.20+ Fix from $2,3002022-05-12 HIGH 7.5 CVE-2022-29298EPSS 47% SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. Sv Cpt Mc310 Firmware No fix yet Fix from $1,9502022-05-12 CRITICAL 9.8 CVE-2022-29596 MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../.… Enterprise Manager No fix yet Fix from $2,3002022-05-11 MEDIUM 5.3 CVE-2022-30058 Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.ph… Shopwind after 3.4.2 Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2022-30059 Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php. Shopwind after 3.4.2 Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2022-30061 ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp. Ftcms after 2.1 Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2022-30062 ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php Ftcms after 2.1 Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2022-1476EPSS 47% The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation… All In One Wp Migration after 7.58 Fix from $1,6002022-05-10 HIGH 7.5 CVE-2022-30333 KEVEPSS 99% RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by … Debian Linux 6.12+ Fix from $1,9502022-05-09 HIGH 8.8 CVE-2022-26889 In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an … Splunk 8.1.2+ Fix from $1,9502022-05-06 MEDIUM 6.5 CVE-2022-24878 Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization… Flux2 0.24.0 / 0.29.0+ Fix from $1,6002022-05-06 HIGH 8.8 CVE-2022-24877 Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization… Flux2 0.24.0 / 0.29.0+ Fix from $1,9502022-05-06 MEDIUM 5.3 CVE-2021-38693 A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulne… Qts 4.5.4.1991 / 5.0.0.1986+ Fix from $1,6002022-05-05 HIGH 7.5 CVE-2021-42183 MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. Masacms No fix yet Fix from $1,9502022-05-05 MEDIUM 5.5 CVE-2022-20101 In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional… Android Mitigation only Fix from $1,6002022-05-03