Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.3 CVE-2024-12830 Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Ng Firewall Mitigation only Fix from $1,9502024-12-20 HIGH 7.5 CVE-2024-38819EPSS 55% Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An atta… Mitigation only Fix from $1,9502024-12-19 CRITICAL 9.1 CVE-2021-26102EPSS 17% A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker … Fortiwan 4.5.8+ Fix from $2,3002024-12-19 HIGH 7.5 CVE-2024-21547 Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:… Patch available Fix from $1,9502024-12-18 MEDIUM 6.5 CVE-2024-56142 pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerability has been discovered that co… Mitigation only Fix from $1,6002024-12-17 CRITICAL 9.1 CVE-2024-55516 A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on… Msg2300 Firmware Mitigation only Fix from $2,3002024-12-17 CRITICAL 9.1 CVE-2024-55513 A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on … Msg2300 Firmware Mitigation only Fix from $2,3002024-12-17 CRITICAL 9.8 CVE-2024-55515 A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the… Msg2300 Firmware Mitigation only Fix from $2,3002024-12-17 HIGH 7.5 CVE-2024-54380 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies Enabler wp-cookies-enabler a… Mitigation only Fix from $1,9502024-12-16 HIGH 7.5 CVE-2024-54373 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmin Booking eduadmin-booking al… Mitigation only Fix from $1,9502024-12-16 HIGH 7.5 CVE-2024-54374 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allows PHP Local File Inclusion.T… Mitigation only Fix from $1,9502024-12-16 HIGH 7.5 CVE-2024-54375 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Woolook woolook allows PHP Local File Inclusion… Mitigation only Fix from $1,9502024-12-16 HIGH 7.5 CVE-2024-55970 File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I64473… Mitigation only Fix from $1,9502024-12-15 MEDIUM 6.5 CVE-2024-54259 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Path Traversal… Mitigation only Fix from $1,6002024-12-13 CRITICAL 9.1 CVE-2024-11833 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affe… Plextrac 2.8.1+ Fix from $2,3002024-12-13 CRITICAL 9.1 CVE-2024-11834 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affe… Plextrac 2.8.1+ Fix from $2,3002024-12-13 MEDIUM 5.4 CVE-2024-8647 An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted inst… GitLab 17.4.6 / 17.5.4+ Fix from $1,6002024-12-12 HIGH 7.5 CVE-2024-55657 SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/ren… Siyuan Patch available Fix from $1,9502024-12-12 HIGH 7.5 CVE-2024-55658 SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary fi… Siyuan Patch available Fix from $1,9502024-12-12 MEDIUM 5.4 CVE-2024-55659 SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary… Siyuan Patch available Fix from $1,6002024-12-12 HIGH 7.8 CVE-2024-54489 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. R… macOS 13.7.2 / 14.7.2+ Fix from $1,9502024-12-12 HIGH 8.8 CVE-2024-55587 python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract. Patch available Fix from $1,9502024-12-12 MEDIUM 6.8 CVE-2024-49082 Windows File Explorer Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20857 / 10.0.14393.7606+ Fix from $1,6002024-12-12 HIGH 8.5 CVE-2024-55602 PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update … Pwndoc after 1.2.1 Fix from $1,9502024-12-10 MEDIUM 5.5 CVE-2024-45709 SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and conf… Web Help Desk 12.8.4+ Fix from $1,6002024-12-10 HIGH 7.7 CVE-2023-6947 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26… Foogallery 2.4.27+ Fix from $1,9502024-12-10 HIGH 8.6 CVE-2024-21542 Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file … Patch available Fix from $1,9502024-12-10 HIGH 8.8 CVE-2024-50626 An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the lo… Connectport Lts Firmware 1.4.12+ Fix from $1,9502024-12-09 HIGH 7.5 CVE-2024-53790 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS lenxel-core… Mitigation only Fix from $1,9502024-12-09 HIGH 7.2 CVE-2024-11010 The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a… Mitigation only Fix from $1,9502024-12-07