Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2023-52334 Allegra downloadAttachmentGlobal Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sen… Allegra 7.5.1+ Fix from $1,6002024-11-22 CRITICAL 9.8 CVE-2023-51639 Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentic… Allegra 7.5.1+ Fix from $2,3002024-11-22 HIGH 8.1 CVE-2024-10220 The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11… Mitigation only Fix from $1,9502024-11-22 MEDIUM 6.5 CVE-2024-52056 Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system… Streaming Engine 4.9.1+ Fix from $1,6002024-11-21 CRITICAL 9.1 CVE-2024-52771 DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view. Dedebiz No fix yet Fix from $2,3002024-11-20 HIGH 7.5 CVE-2024-52448 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-… Mitigation only Fix from $1,9502024-11-20 HIGH 7.5 CVE-2024-52449 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscraper allows PHP Local File Incl… Mitigation only Fix from $1,9502024-11-20 HIGH 7.5 CVE-2024-52444 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-cus… Mitigation only Fix from $1,9502024-11-20 MEDIUM 5.3 CVE-2024-52600 Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames… Patch available Fix from $1,6002024-11-19 MEDIUM 6.5 CVE-2024-48071 E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to pe… E Cology Mitigation only Fix from $1,6002024-11-19 HIGH 8.1 CVE-2020-3538 A vulnerability in a certain REST API endpoint of Cisco&nbsp;Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacke… Data Center Network Manager 11.4+ Fix from $1,9502024-11-18 HIGH 8.4 CVE-2020-26071 A vulnerability in the CLI of Cisco&nbsp;SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an af… Catalyst Sd Wan Manager Mitigation only Fix from $1,9502024-11-18 HIGH 8.7 CVE-2024-11303 The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issu… Mitigation only Fix from $1,9502024-11-18 HIGH 8.1 CVE-2024-41971 A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss. No fix yet Fix from $1,9502024-11-18 CRITICAL 9.8 CVE-2024-11315 The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker… Dvc 6.4+ Fix from $2,3002024-11-18 CRITICAL 9.8 CVE-2024-11313 The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker… Dvc 6.4+ Fix from $2,3002024-11-18 CRITICAL 9.8 CVE-2024-11314 The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker… Dvc 6.4+ Fix from $2,3002024-11-18 CRITICAL 9.8 CVE-2024-11312 The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker… Dvc 6.4+ Fix from $2,3002024-11-18 CRITICAL 9.8 CVE-2024-11311 The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attacker… Dvc 6.4+ Fix from $2,3002024-11-18 HIGH 7.5 CVE-2024-11309 The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary sys… Dvc 6.4+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-11310 The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary sys… Dvc 6.4+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-9935EPSS 7% The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 v… Mitigation only Fix from $1,9502024-11-16 HIGH 8.8 CVE-2024-44625EPSS 15% Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go. Gogs after 0.13.0 Fix from $1,9502024-11-15 CRITICAL 9.8 CVE-2024-50648 yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP … Yshopmall No fix yet Fix from $2,3002024-11-15 CRITICAL 9.8 CVE-2024-50649 The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability. Python Book No fix yet Fix from $2,3002024-11-15 HIGH 7.5 CVE-2024-41784 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An att… Sterling Secure Proxy Mitigation only Fix from $1,9502024-11-15 MEDIUM 5.3 CVE-2024-11238EPSS 6% A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/… Landray Ekp after 16.0 Fix from $1,6002024-11-15 MEDIUM 5.3 CVE-2024-42499 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerabi… Mitigation only Fix from $1,6002024-11-15 HIGH 8.8 CVE-2024-52396 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.Thi… Wolf Wordpress Posts Bulk Editor And Products Manager Professional 1.0.8.4+ Fix from $1,9502024-11-14 HIGH 7.5 CVE-2024-52378 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass allows Absolute Path Travers… Mitigation only Fix from $1,9502024-11-14