Total
6543 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-39059 | 1 Changingtec | 1 Megaservisignadapter | 2024-11-21 | N/A | 7.5 HIGH |
ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files. | |||||
CVE-2022-39058 | 1 Changingtec | 1 Rava Certificate Validation System | 2024-11-21 | N/A | 7.5 HIGH |
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. | |||||
CVE-2022-39045 | 1 Siretta | 2 Quartz-gold, Quartz-gold Firmware | 2024-11-21 | N/A | 8.8 HIGH |
A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability. | |||||
CVE-2022-39040 | 1 Aenrich | 1 A\+hrd | 2024-11-21 | N/A | 7.5 HIGH |
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. | |||||
CVE-2022-39037 | 1 Flowring | 1 Agentflow | 2024-11-21 | N/A | 7.5 HIGH |
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. | |||||
CVE-2022-39034 | 1 Lcnet | 1 Smart Evision | 2024-11-21 | N/A | 6.5 MEDIUM |
Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication, access restricted paths and download system files. | |||||
CVE-2022-39033 | 1 Lcnet | 1 Smart Evision | 2024-11-21 | N/A | 9.8 CRITICAL |
Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service. | |||||
CVE-2022-39023 | 1 Edetw | 1 U-office Force | 2024-11-21 | N/A | 6.5 MEDIUM |
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file. | |||||
CVE-2022-39022 | 1 Edetw | 1 U-office Force | 2024-11-21 | N/A | 6.5 MEDIUM |
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file. | |||||
CVE-2022-39001 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2024-11-21 | N/A | 7.5 HIGH |
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. | |||||
CVE-2022-38794 | 1 Zaver Project | 1 Zaver | 2024-11-21 | N/A | 7.5 HIGH |
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring. | |||||
CVE-2022-38731 | 1 Qaelum | 1 Dose | 2024-11-21 | N/A | 4.3 MEDIUM |
Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbitrary location on the server's filesystem from which to load an image. (Only images are displayed to the attacker. All other files are loaded but not displayed.) The Content-Type response header reflects the actual content type of the file being requested. This allows an attacker to enumerate files on the local system. Additionally, remote resources can be requested via a UNC path, allowing an attacker to coerce authentication out from the server to the attackers machine. | |||||
CVE-2022-38723 | 1 Gravitee | 1 Api Management | 2024-11-21 | N/A | 8.6 HIGH |
Gravitee API Management before 3.15.13 allows path traversal through HTML injection. | |||||
CVE-2022-38638 | 1 Casbin | 1 Casdoor | 2024-11-21 | N/A | 9.1 CRITICAL |
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. | |||||
CVE-2022-38614 | 1 Bpcbt | 1 Smartvista Cardgen | 2024-11-21 | N/A | 7.5 HIGH |
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter. | |||||
CVE-2022-38613 | 1 Bpcbt | 1 Smartvista Cardgen | 2024-11-21 | N/A | 6.5 MEDIUM |
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system. | |||||
CVE-2022-38485 | 1 Agevolt | 1 Agevolt | 2024-11-21 | N/A | 6.5 MEDIUM |
A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated attacker could leverage this vulnerability to read files from any location on the target operating system with web server privileges. | |||||
CVE-2022-38484 | 1 Agevolt | 1 Agevolt | 2024-11-21 | N/A | 8.8 HIGH |
An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with web server privileges. | |||||
CVE-2022-38451 | 2 Freshtomato, Siretta | 3 Freshtomato, Quartz-gold, Quartz-gold Firmware | 2024-11-21 | N/A | 7.5 HIGH |
A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability. | |||||
CVE-2022-38424 | 1 Adobe | 1 Coldfusion | 2024-11-21 | N/A | 7.2 HIGH |
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges. |