Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-1554
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
Scout
4.52+
HIGH 7.5
CVE-2022-24897
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.…
Xwiki
12.6.7 / 12.10.3+
HIGH 7.5
CVE-2022-29970
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Debian Linux
2.2.0+
HIGH 7.5
CVE-2022-28451
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
Nopcommerce
Patch available
CRITICAL 9.8
CVE-2022-25842
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a s…
One Java Agent
Patch available
HIGH 7.5
CVE-2022-26068
This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.
Pistache
0.0.3.20220425+
HIGH 7.5
CVE-2022-29967
static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.
Glewlwyd
after 2.6.2
HIGH 8.6
CVE-2022-24900EPSS 8%
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vuln…
Piano Led Visualizer
after 1.3
CRITICAL 9.8
CVE-2022-29081EPSS 84%
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass …
Manageengine Access Manager Plus
No fix yet
HIGH 7.5
CVE-2021-46420EPSS 6%
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to …
Ts 550 Evo Firmware
No fix yet
HIGH 7.5
CVE-2021-46421EPSS 6%
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to ob…
Ts 550 Evo Firmware
No fix yet
HIGH 8.1
CVE-2022-28058
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
Verydows
No fix yet
HIGH 8.1
CVE-2022-28059
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
Verydows
No fix yet
HIGH 8.1
CVE-2022-28523
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
Hongcms
No fix yet
HIGH 8.1
CVE-2022-28527
dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.
Dhcms
No fix yet
HIGH 8.8
CVE-2021-26629
A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompre…
Xplatform
9.2.2.284+
CRITICAL 9.8
CVE-2022-29806EPSS 67%
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contribut…
Zoneminder
1.36.13+
HIGH 7.5
CVE-2021-35250EPSS 13%
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se…
Serv U
Mitigation only
CRITICAL 9.8
CVE-2022-23457
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default imp…
Active Iq Unified Manager
2.3.0.0+
CRITICAL 9.8
CVE-2022-1390EPSS 22%
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated …
Admin Word Count Column
after 2.2
CRITICAL 9.8
CVE-2022-1391EPSS 15%
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could l…
Cab Fare Calculator
1.0.4+
HIGH 7.5
CVE-2022-1392EPSS 11%
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Loc…
Videos Sync Pdf
after 1.7.4
HIGH 8.1
CVE-2021-40680
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via th…
Web Proxy
Mitigation only
HIGH 7.5
CVE-2022-24424
Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially…
Emc Appsync
4.4.0.0+
HIGH 7.5
CVE-2022-28444
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
Ucms
No fix yet
MEDIUM 6.5
CVE-2022-20790
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager S…
Unified Communications Manager
after 14.0
HIGH 7.2
CVE-2022-27925 KEVEPSS 99%
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated u…
Zimbra Collaboration Suite
Mitigation only
MEDIUM 5.9
CVE-2021-43988
The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized acce…
Roboguide
after 9.40083.00.05
HIGH 7.5
CVE-2022-1119EPSS 20%
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php fil…
Simple File List
3.2.8+
HIGH 8.8
CVE-2021-44519
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
Xenmobile Server
Mitigation only