Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2024-44034 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File In… Mitigation only Fix from $1,9502024-10-05 MEDIUM 6.6 CVE-2024-47309 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Condless Cities Shipping Zones for WooCommerce cities… Mitigation only Fix from $1,6002024-10-05 HIGH 7.5 CVE-2024-44018 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPre… Mitigation only Fix from $1,9502024-10-05 HIGH 7.5 CVE-2024-44016 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File I… Mitigation only Fix from $1,9502024-10-05 HIGH 7.5 CVE-2024-44011 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Suppo… Mitigation only Fix from $1,9502024-10-05 HIGH 7.5 CVE-2024-44012 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subs… Mitigation only Fix from $1,9502024-10-05 HIGH 7.5 CVE-2024-44013 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows… Mitigation only Fix from $1,9502024-10-05 CRITICAL 9.6 CVE-2024-44014 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager… Mitigation only Fix from $2,3002024-10-05 HIGH 7.5 CVE-2024-44015 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP L… Mitigation only Fix from $1,9502024-10-05 HIGH 7.5 CVE-2024-47841EPSS 35% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension al… Wikimedia Extensions Css 1.39.9 / 1.41.3+ Fix from $1,9502024-10-05 HIGH 7.5 CVE-2024-47769 IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here… Idurar after 4.1.0 Fix from $1,9502024-10-04 HIGH 7.5 CVE-2024-41163EPSS 52% A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a d… Anka Build Cloud No fix yet Fix from $1,9502024-10-03 HIGH 7.5 CVE-2024-41922EPSS 8% A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can … Anka Build Cloud No fix yet Fix from $1,9502024-10-03 MEDIUM 6.5 CVE-2024-9100 Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. Mitigation only Fix from $1,6002024-10-03 HIGH 7.5 CVE-2024-8352 The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up… Social Web Suite 4.1.12+ Fix from $1,9502024-10-03 MEDIUM 6.5 CVE-2024-46977 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerabilit… Cosmos 5.19.0+ Fix from $1,6002024-10-02 HIGH 8.8 CVE-2024-20449 A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitr… Nexus Dashboard Fabric Controller after 12.2.2 Fix from $1,9502024-10-02 HIGH 7.5 CVE-2024-44017 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File… Mitigation only Fix from $1,9502024-10-02 HIGH 7.2 CVE-2024-44030 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp… Mitigation only Fix from $1,9502024-10-02 HIGH 7.2 CVE-2024-25659 In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows… Transcend Network Management System Mitigation only Fix from $1,9502024-10-01 MEDIUM 6.8 CVE-2024-47071 OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized… Patch available Fix from $1,6002024-10-01 MEDIUM 6.5 CVE-2024-9224 The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() … Hello World 2.2.0+ Fix from $1,6002024-10-01 HIGH 8.8 CVE-2024-33369 Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromC… Rpshare Mitigation only Fix from $1,9502024-09-27 HIGH 7.5 CVE-2024-9301 A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a E2nest 2024-09-05+ Fix from $1,9502024-09-27 HIGH 8.8 CVE-2024-7149 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… Eventin 4.0.9+ Fix from $1,9502024-09-27 MEDIUM 5.5 CVE-2024-47292 Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,6002024-09-27 MEDIUM 5.7 CVE-2024-46327 An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal. Vap11g 300 Firmware Mitigation only Fix from $1,6002024-09-26 HIGH 7.2 CVE-2024-8704 The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the '… Advanced File Manager 5.2.9+ Fix from $1,9502024-09-26 HIGH 7.5 CVE-2024-44825 Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files… Mitigation only Fix from $1,9502024-09-25 MEDIUM 5.3 CVE-2024-8941 Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allo… Scriptcase Mitigation only Fix from $1,6002024-09-25