Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.6 CVE-2024-52371 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway e4 | Payeezy Gateway | globe-… Mitigation only Fix from $1,9502024-11-14 MEDIUM 5.4 CVE-2024-11210 A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logi… Eyoucms No fix yet Fix from $1,6002024-11-14 MEDIUM 5.3 CVE-2024-50843 A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to… User Registration \& Login And User Management System No fix yet Fix from $1,6002024-11-14 MEDIUM 6.5 CVE-2024-11215 Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. … Webserver Mitigation only Fix from $1,6002024-11-14 HIGH 7.5 CVE-2024-47916 Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Mitigation only Fix from $1,9502024-11-14 HIGH 7.5 CVE-2024-45253 Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Mitigation only Fix from $1,9502024-11-14 MEDIUM 6.0 CVE-2024-2552 A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the m… Pan Os 10.2.7 / 11.0.6+ Fix from $1,6002024-11-14 HIGH 7.1 CVE-2024-21799 Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalat… Mitigation only Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-52291 Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a doub… Craft Cms 4.12.5 / 5.4.6+ Fix from $1,9502024-11-13 MEDIUM 6.5 CVE-2024-52292 Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templat… Craft Cms 4.12.8 / 5.4.9+ Fix from $1,6002024-11-13 HIGH 7.2 CVE-2024-52293 Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could … Craft Cms 4.12.2 / 5.4.3+ Fix from $1,9502024-11-13 CRITICAL 9.8 CVE-2024-48510 Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry… Prodotnetzip 1.19.0+ Fix from $2,3002024-11-13 CRITICAL 9.8 CVE-2024-11150 The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_… User Extra Fields 16.7+ Fix from $2,3002024-11-13 HIGH 7.5 CVE-2024-10816 The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.… Mitigation only Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-34787EPSS 18% Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at… Endpoint Manager 2022+ Fix from $1,9502024-11-13 MEDIUM 6.0 CVE-2024-32116 Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer versio… Fortianalyzer 7.2.6 / 7.2.8+ Fix from $1,6002024-11-12 MEDIUM 5.3 CVE-2024-50336 matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path travers… Mitigation only Fix from $1,6002024-11-12 HIGH 8.8 CVE-2024-50329 Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated a… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-50322EPSS 6% Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-50324EPSS 19% Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated att… Endpoint Manager 2022+ Fix from $1,9502024-11-12 CRITICAL 9.9 CVE-2024-46888 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provide… Sinec Ins 1.0+ Fix from $2,3002024-11-12 HIGH 7.5 CVE-2024-11123 A vulnerability, which was classified as problematic, was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. This affects an unknown part … Lingdang Crm after 8.6.4.3 Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-51747 Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files f… Kanboard 1.2.42+ Fix from $1,9502024-11-11 HIGH 7.2 CVE-2024-51748 Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the ser… Kanboard 1.2.42+ Fix from $1,9502024-11-11 HIGH 7.8 CVE-2024-46954 An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directo… Ghostscript 10.04.0+ Fix from $1,9502024-11-10 CRITICAL 9.8 CVE-2024-10470EPSS 34% The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insuff… Wordpress Learning Management System 4.963+ Fix from $2,3002024-11-09 CRITICAL 9.1 CVE-2024-10625 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d… Woocommerce Support Ticket System 17.8+ Fix from $2,3002024-11-09 HIGH 8.1 CVE-2024-10626 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the d… Woocommerce Support Ticket System 17.8+ Fix from $1,9502024-11-09 HIGH 8.6 CVE-2024-51998 changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attack… Patch available Fix from $1,9502024-11-08 HIGH 8.1 CVE-2024-43434 The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerabil… Moodle 4.1.12 / 4.2.9+ Fix from $1,9502024-11-07