Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2024-49381 Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to … Plenti 0.7.2+ Fix from $1,9502024-10-25 HIGH 7.5 CVE-2024-10379 A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the fil… Cdg No fix yet Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47027 In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This coul… Android Mitigation only Fix from $1,9502024-10-25 MEDIUM 5.3 CVE-2024-45842 Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files m… E Studio1058 Firmware Mitigation only Fix from $1,6002024-10-25 HIGH 8.1 CVE-2024-10011 The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This make… Buddypress after 14.1.0 Fix from $1,9502024-10-25 HIGH 7.5 CVE-2024-49359 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpo… Zimaos 1.2.5+ Fix from $1,9502024-10-24 MEDIUM 5.3 CVE-2024-49760 OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the… Openrefine 3.8.3+ Fix from $1,6002024-10-24 HIGH 7.5 CVE-2024-48931 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS AP… Zimaos 1.2.5+ Fix from $1,9502024-10-24 CRITICAL 9.1 CVE-2024-47883 The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class … Butterfly after 1.2.6 Fix from $2,3002024-10-24 HIGH 8.8 CVE-2024-45262 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call met… Mt2500 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 8.0 CVE-2024-10313 iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template f… Mitigation only Fix from $1,9502024-10-24 MEDIUM 6.5 CVE-2024-20379 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center… Firepower Management Center Mitigation only Fix from $1,6002024-10-23 CRITICAL 9.8 CVE-2024-41717 Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the sy… Mitigation only Fix from $2,3002024-10-22 HIGH 8.8 CVE-2024-35308 A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: … Pandora Fms 777.3+ Fix from $1,9502024-10-22 CRITICAL 9.1 CVE-2024-41713 KEVEPSS 98% A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated att… Micollab after 9.8.1.201 Fix from $2,3002024-10-21 HIGH 7.5 CVE-2024-49366 Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verificatio… Nginx Ui after 1.9.9-4 Fix from $1,9502024-10-21 HIGH 7.5 CVE-2024-45309EPSS 25% OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary f… Onedev 11.0.9+ Fix from $1,9502024-10-21 HIGH 7.8 CVE-2024-47742 In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Block path traversal Most firmware names are hardcoded strings… Debian Linux 4.19.323 / 5.4.285+ Fix from $1,9502024-10-21 HIGH 7.5 CVE-2024-10200 Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner… Administrative Management System Mitigation only Fix from $1,9502024-10-21 CRITICAL 9.8 CVE-2024-49286 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Events ssv-events allows PHP Loca… Ssv Events after 3.2.7 Fix from $2,3002024-10-20 HIGH 7.5 CVE-2024-10100 A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of the file parameter,… Gpt Academic No fix yet Fix from $1,9502024-10-17 HIGH 7.5 CVE-2024-49285 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV MailChimp ssv-mailchimp allows PH… Mitigation only Fix from $1,9502024-10-17 HIGH 7.5 CVE-2024-49287 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Rechnungsverwaltung pdf-rechnun… Mitigation only Fix from $1,9502024-10-17 HIGH 8.6 CVE-2024-49315 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager… Mitigation only Fix from $1,9502024-10-17 HIGH 7.5 CVE-2024-49245 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.T… Mitigation only Fix from $1,9502024-10-16 HIGH 8.8 CVE-2024-47637 Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca… Litespeed Cache 6.5.1+ Fix from $1,9502024-10-16 HIGH 7.5 CVE-2024-47645 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpopti… Mitigation only Fix from $1,9502024-10-16 HIGH 7.5 CVE-2024-47351 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path T… Mitigation only Fix from $1,9502024-10-16 HIGH 8.8 CVE-2024-45711EPSS 6% SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the… Serv U 15.5+ Fix from $1,9502024-10-16 HIGH 8.0 CVE-2020-36836 The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a la… Wp Fastest Cache 0.9.0.3+ Fix from $1,9502024-10-16