Total
7420 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-1554 | 1 Clinical-genomics | 1 Scout | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. | |||||
CVE-2022-1518 | 1 Illumina | 8 Iseq 100, Local Run Manager, Miniseq and 5 more | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure. | |||||
CVE-2022-1476 | 1 Servmask | 1 All-in-one Wp Migration | 2024-11-21 | 5.5 MEDIUM | 6.6 MEDIUM |
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key. | |||||
CVE-2022-1392 | 1 Commoninja | 1 Videos Sync Pdf | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues | |||||
CVE-2022-1391 | 1 Kanev | 1 Cab Fare Calculator | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues. | |||||
CVE-2022-1390 | 1 Admin Word Count Column Project | 1 Admin Word Count Column | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique | |||||
CVE-2022-1373 | 1 Softing | 6 Edgeaggregator, Edgeconnector, Opc and 3 more | 2024-11-21 | N/A | 7.2 HIGH |
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk. | |||||
CVE-2022-1359 | 1 Cambiumnetworks | 1 Cnmaestro | 2024-11-21 | 5.0 MEDIUM | 5.7 MEDIUM |
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server. | |||||
CVE-2022-1264 | 1 Inductiveautomation | 1 Ignition | 2024-11-21 | N/A | 6.8 MEDIUM |
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code. | |||||
CVE-2022-1166 | 1 Nootheme | 1 Jobmonster | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors can also take measures to make it less likely to happen. | |||||
CVE-2022-1128 | 2 Google, Microsoft | 2 Chrome, Windows | 2024-11-21 | N/A | 6.5 MEDIUM |
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page. | |||||
CVE-2022-1119 | 1 Simplefilelist | 1 Simple-file-list | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7. | |||||
CVE-2022-1000 | 1 Tiny File Manager Project | 1 Tiny File Manager | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. | |||||
CVE-2022-0902 | 1 Abb | 14 Rmc-100, Rmc-100-lite, Rmc-100-lite Firmware and 11 more | 2024-11-21 | N/A | 8.1 HIGH |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node. | |||||
CVE-2022-0779 | 1 User-meta | 1 User Meta User Profile Builder And User Management | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the web server via path traversal payloads | |||||
CVE-2022-0679 | 1 Narnoo Distributor Project | 1 Narnoo Distributor | 2024-11-21 | 6.8 MEDIUM | 9.8 CRITICAL |
The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as the content of the file is then displayed in the response as JSON data. This could also lead to RCE with various tricks but depends on the underlying system and it's configuration. | |||||
CVE-2022-0673 | 1 Eclipse | 1 Lemminx | 2024-11-21 | 6.4 MEDIUM | 6.5 MEDIUM |
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal. | |||||
CVE-2022-0665 | 1 Pimcore | 1 Pimcore | 2024-11-21 | 5.5 MEDIUM | 6.5 MEDIUM |
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2. | |||||
CVE-2022-0493 | 1 String Locator Project | 1 String Locator | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will be used to output the relevant matches from the matching file, all content of the file can be disclosed. | |||||
CVE-2022-0436 | 1 Gruntjs | 1 Grunt | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2. |