Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2019-25213 The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due t… Advanced Access Manager after 5.9.8.1 Fix from $1,9502024-10-16 CRITICAL 9.1 CVE-2024-48914EPSS 60% Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an a… Patch available Fix from $2,3002024-10-15 MEDIUM 6.5 CVE-2024-9676 A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda… Openshift Container Platform Patch available Fix from $1,6002024-10-15 HIGH 7.5 CVE-2024-9983 Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this … Enterprise Cloud Database 2024-08-08+ Fix from $1,9502024-10-15 HIGH 7.5 CVE-2024-46898 SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploite… Shirasagi 1.19.1+ Fix from $1,9502024-10-15 HIGH 7.8 CVE-2024-0129 NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A succ… Nemo Mitigation only Fix from $1,9502024-10-15 HIGH 8.0 CVE-2024-45731 In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles… Splunk 9.1.6 / 9.2.3+ Fix from $1,9502024-10-14 CRITICAL 9.8 CVE-2024-9047EPSS 93% The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.… Wordpress File Upload 4.24.12+ Fix from $2,3002024-10-12 HIGH 7.5 CVE-2024-47877 Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symli… Extract 4.0.0+ Fix from $1,9502024-10-11 MEDIUM 6.5 CVE-2024-7514 The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during t… Mitigation only Fix from $1,6002024-10-11 HIGH 7.5 CVE-2024-47868 Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio componen… Gradio 5.0.0+ Fix from $1,9502024-10-10 MEDIUM 6.5 CVE-2024-47164 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** wi… Gradio 5.0.0+ Fix from $1,6002024-10-10 MEDIUM 5.3 CVE-2024-47166 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/cust… Gradio 4.44.0+ Fix from $1,6002024-10-10 HIGH 7.2 CVE-2024-7037 In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized fi… Open Webui No fix yet Fix from $1,9502024-10-09 HIGH 8.5 CVE-2024-9575 Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pre… Mitigation only Fix from $1,9502024-10-09 HIGH 7.1 CVE-2024-47191 pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, … Patch available Fix from $1,9502024-10-09 HIGH 7.2 CVE-2024-9381EPSS 16% Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. Endpoint Manager Cloud Services Appliance 5.0.2+ Fix from $1,9502024-10-08 CRITICAL 9.8 CVE-2024-47010EPSS 38% Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. Avalanche 6.4.5+ Fix from $2,3002024-10-08 HIGH 7.5 CVE-2024-47011EPSS 56% Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information Avalanche 6.4.5+ Fix from $1,9502024-10-08 CRITICAL 9.8 CVE-2024-47009 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. Avalanche 6.4.5+ Fix from $2,3002024-10-08 HIGH 7.5 CVE-2024-47948 In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups Teamcity 2024.07.3+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-47949EPSS 23% In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location Teamcity 2024.07.3+ Fix from $1,9502024-10-08 MEDIUM 5.3 CVE-2024-47563 A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file pat… Sinec Security Monitor 4.9.0+ Fix from $1,6002024-10-08 MEDIUM 6.5 CVE-2024-47818 Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesy… Patch available Fix from $1,6002024-10-07 HIGH 8.8 CVE-2024-45291 PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links im… Phpspreadsheet 1.29.2 / 2.1.1+ Fix from $1,9502024-10-07 CRITICAL 9.8 CVE-2024-47556 Pre-Auth RCE via Path Traversal Freeflow Core 7.0.11+ Fix from $2,3002024-10-07 CRITICAL 9.8 CVE-2024-47557 Pre-Auth RCE via Path Traversal Freeflow Core 7.0.11+ Fix from $2,3002024-10-07 HIGH 8.8 CVE-2024-47558 Authenticated RCE via Path Traversal Freeflow Core Mitigation only Fix from $1,9502024-10-07 HIGH 8.8 CVE-2024-47559 Authenticated RCE via Path Traversal Freeflow Core Mitigation only Fix from $1,9502024-10-07 CRITICAL 9.8 CVE-2024-46446 Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can the… Mecha No fix yet Fix from $2,3002024-10-07