Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.1 CVE-2024-10516EPSS 6% The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajax… Mitigation only Fix from $1,9502024-12-06 HIGH 7.5 CVE-2024-11585 The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficien… Mitigation only Fix from $1,9502024-12-06 HIGH 7.5 CVE-2024-53523 JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function. Mitigation only Fix from $1,9502024-12-05 MEDIUM 5.5 CVE-2024-10933 In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversa… OpenBSD 7.4+ Fix from $1,6002024-12-05 HIGH 7.5 CVE-2024-53490 Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java. Mitigation only Fix from $1,9502024-12-05 CRITICAL 9.4 CVE-2024-51549 Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.  Affected products: ABB ASPECT - Enterprise v3.08… Aspect Ent 12 Firmware 3.08.03+ Fix from $2,3002024-12-05 MEDIUM 6.3 CVE-2024-54132 The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite file… Patch available Fix from $1,6002024-12-04 CRITICAL 9.8 CVE-2024-54154 In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox Youtrack 2024.3.51866+ Fix from $2,3002024-12-04 HIGH 7.5 CVE-2024-11952 The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and includin… Mitigation only Fix from $1,9502024-12-04 HIGH 8.1 CVE-2024-11398 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (S… Router Manager 1.3.1-9346+ Fix from $1,9502024-12-04 MEDIUM 5.5 CVE-2024-53566 An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path … Debian Linux Mitigation only Fix from $1,6002024-12-02 CRITICAL 9.8 CVE-2024-46909EPSS 49% In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context… Whatsup Gold 24.0.1+ Fix from $2,3002024-12-02 HIGH 8.4 CVE-2024-49360 Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (**UserA**) with no p… Sandboxie 1.14.6 / 5.69.6+ Fix from $1,9502024-11-29 CRITICAL 9.1 CVE-2024-11992 Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictio… Mitigation only Fix from $2,3002024-11-29 HIGH 8.2 CVE-2024-11481 A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, inse… Enterprise Security Manager Mitigation only Fix from $1,9502024-11-29 HIGH 7.5 CVE-2024-52481 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify jobify allows Relative Path Travers… Jobify 4.2.4+ Fix from $1,9502024-11-28 HIGH 7.2 CVE-2024-9669 The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via… Filester 1.8.6+ Fix from $1,9502024-11-28 CRITICAL 9.8 CVE-2024-11667 KEV A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwa… Zld after 5.38 Fix from $2,3002024-11-27 HIGH 7.5 CVE-2024-11219 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up … Otter Blocks 3.0.7+ Fix from $1,9502024-11-27 CRITICAL 9.8 CVE-2024-53676EPSS 52% A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. Insight Remote Support 7.14.0.629+ Fix from $2,3002024-11-27 MEDIUM 6.3 CVE-2024-53844 E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup ex… Mitigation only Fix from $1,6002024-11-26 HIGH 7.5 CVE-2024-33605EPSS 6% Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product… No fix yet Fix from $1,9502024-11-26 CRITICAL 9.1 CVE-2024-52787 An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uplo… Patch available Fix from $2,3002024-11-25 CRITICAL 9.8 CVE-2024-11664 A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of … Enms 4.2+ Fix from $2,3002024-11-25 HIGH 7.5 CVE-2024-10803 The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.0 via the content/downloader.… Mitigation only Fix from $1,9502024-11-23 HIGH 7.8 CVE-2024-7565 SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Soapui Mitigation only Fix from $1,9502024-11-22 HIGH 7.2 CVE-2024-5581 Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af… Allegra 7.5.2+ Fix from $1,9502024-11-22 MEDIUM 6.5 CVE-2023-51648 Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensi… Allegra 7.5.1+ Fix from $1,6002024-11-22 HIGH 7.5 CVE-2023-52332 Allegra serveMathJaxLibraries Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensit… Allegra 7.5.1+ Fix from $1,9502024-11-22 HIGH 7.3 CVE-2023-52333 Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff… Allegra 7.5.1+ Fix from $1,9502024-11-22