CWE-31 · 7 записей
Path Traversal: 'dir\..\..\filename'
CVE этого класса
7 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2024-2044Готовый эксплойт | Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4pgadmin · pgadmin 4 · CWE-31 | Критическая9,9 | — | 79,5 % | 7 мар. 2024 г. |
36Наблюдать | CVE-2024-24998Эксплойта нет | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryivanti · avalanche · CWE-31 | Высокая8,8 | — | 3,2 % | 18 апр. 2024 г. |
35Наблюдать | CVE-2024-41376Эксплойта нет | dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.dzzoffice · dzzoffice · CWE-31 | Высокая8,8 | — | 1,0 % | 5 авг. 2024 г. |
31Наблюдать | CVE-2024-36857Proof of concept | Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.homebrew · jan · CWE-31 | Высокая7,5 | — | 2,1 % | 4 июн. 2024 г. |
30Наблюдать | CVE-2024-35431Эксплойта нет | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64.zkteco · zkbio cvsecurity · CWE-31 | Высокая7,5 | — | 1,0 % | 30 мая 2024 г. |
30Наблюдать | CVE-2019-6268Эксплойта нет | RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /..CWE-31 | Высокая7,5 | — | 0,8 % | 7 мар. 2024 г. |
30Наблюдать | CVE-2024-25840Эксплойта нет | In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guprestaworld · account manager · CWE-31 | Высокая7,5 | — | 0,6 % | 27 февр. 2024 г. |
- CVE-2024-204463На этой неделе
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
КритическаяCVSS 9,9Готовый эксплойтEPSS 79 %pgadmin · pgadmin 47 мар. 2024 г.
- CVE-2024-2499836Наблюдать
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %ivanti · avalanche18 апр. 2024 г.
- CVE-2024-4137635Наблюдать
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dzzoffice · dzzoffice5 авг. 2024 г.
- CVE-2024-3685731Наблюдать
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %homebrew · jan4 июн. 2024 г.
- CVE-2024-3543130Наблюдать
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zkteco · zkbio cvsecurity30 мая 2024 г.
- CVE-2019-626830Наблюдать
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /..
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %7 мар. 2024 г.
- CVE-2024-2584030Наблюдать
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a gu
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %prestaworld · account manager27 февр. 2024 г.