Vulnerabilities (CVE)

Filtered by CWE-22
Total 6543 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-39059 1 Changingtec 1 Megaservisignadapter 2024-11-21 N/A 7.5 HIGH
ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
CVE-2022-39058 1 Changingtec 1 Rava Certificate Validation System 2024-11-21 N/A 7.5 HIGH
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
CVE-2022-39045 1 Siretta 2 Quartz-gold, Quartz-gold Firmware 2024-11-21 N/A 8.8 HIGH
A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-39040 1 Aenrich 1 A\+hrd 2024-11-21 N/A 7.5 HIGH
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
CVE-2022-39037 1 Flowring 1 Agentflow 2024-11-21 N/A 7.5 HIGH
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
CVE-2022-39034 1 Lcnet 1 Smart Evision 2024-11-21 N/A 6.5 MEDIUM
Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files.
CVE-2022-39033 1 Lcnet 1 Smart Evision 2024-11-21 N/A 9.8 CRITICAL
Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.
CVE-2022-39023 1 Edetw 1 U-office Force 2024-11-21 N/A 6.5 MEDIUM
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
CVE-2022-39022 1 Edetw 1 U-office Force 2024-11-21 N/A 6.5 MEDIUM
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
CVE-2022-39001 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 N/A 7.5 HIGH
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.
CVE-2022-38794 1 Zaver Project 1 Zaver 2024-11-21 N/A 7.5 HIGH
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
CVE-2022-38731 1 Qaelum 1 Dose 2024-11-21 N/A 4.3 MEDIUM
Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbitrary location on the server's filesystem from which to load an image. (Only images are displayed to the attacker. All other files are loaded but not displayed.) The Content-Type response header reflects the actual content type of the file being requested. This allows an attacker to enumerate files on the local system. Additionally, remote resources can be requested via a UNC path, allowing an attacker to coerce authentication out from the server to the attackers machine.
CVE-2022-38723 1 Gravitee 1 Api Management 2024-11-21 N/A 8.6 HIGH
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
CVE-2022-38638 1 Casbin 1 Casdoor 2024-11-21 N/A 9.1 CRITICAL
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CVE-2022-38614 1 Bpcbt 1 Smartvista Cardgen 2024-11-21 N/A 7.5 HIGH
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
CVE-2022-38613 1 Bpcbt 1 Smartvista Cardgen 2024-11-21 N/A 6.5 MEDIUM
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
CVE-2022-38485 1 Agevolt 1 Agevolt 2024-11-21 N/A 6.5 MEDIUM
A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated attacker could leverage this vulnerability to read files from any location on the target operating system with web server privileges.
CVE-2022-38484 1 Agevolt 1 Agevolt 2024-11-21 N/A 8.8 HIGH
An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with web server privileges.
CVE-2022-38451 2 Freshtomato, Siretta 3 Freshtomato, Quartz-gold, Quartz-gold Firmware 2024-11-21 N/A 7.5 HIGH
A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-38424 1 Adobe 1 Coldfusion 2024-11-21 N/A 7.2 HIGH
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges.