Search Results (8002 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-39858 1 Samsung 1 Factorycamera 2024-11-21 7.3 High
Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.
CVE-2022-39838 1 Systematicalpha 2 Systematic Fix Adapter, Systematic Fix Adapter Firmware 2024-11-21 8.6 High
Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.
CVE-2022-39802 1 Sap 1 Manufacturing Execution 2024-11-21 7.5 High
SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.
CVE-2022-39045 1 Siretta 2 Quartz-gold, Quartz-gold Firmware 2024-11-21 8.8 High
A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-38794 1 Zaver Project 1 Zaver 2024-11-21 7.5 High
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
CVE-2022-38638 1 Casbin 1 Casdoor 2024-11-21 9.1 Critical
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CVE-2022-38614 1 Bpcbt 1 Smartvista Cardgen 2024-11-21 7.5 High
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
CVE-2022-38613 1 Bpcbt 1 Smartvista Cardgen 2024-11-21 6.5 Medium
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
CVE-2022-38485 1 Agevolt 1 Agevolt 2024-11-21 6.5 Medium
A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated attacker could leverage this vulnerability to read files from any location on the target operating system with web server privileges.
CVE-2022-38484 1 Agevolt 1 Agevolt 2024-11-21 8.8 High
An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with web server privileges.
CVE-2022-38451 2 Freshtomato, Siretta 3 Freshtomato, Quartz-gold, Quartz-gold Firmware 2024-11-21 7.5 High
A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-38301 1 Onedev Project 1 Onedev 2024-11-21 8.8 High
Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.
CVE-2022-38258 1 Dlink 2 Dir-819, Dir-819 Firmware 2024-11-21 8.1 High
A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server information via manipulation of the getpage parameter in a crafted web request.
CVE-2022-38088 1 Siretta 2 Quartz-gold, Quartz-gold Firmware 2024-11-21 6.5 Medium
A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-37700 1 Easycorp 1 Zentao 2024-11-21 7.5 High
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
CVE-2022-37423 1 Neo4j 1 Awesome Procedures On Cypher 2024-11-21 7.5 High
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
CVE-2022-37422 1 Payara 1 Payara 2024-11-21 7.5 High
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.
CVE-2022-37299 1 Shirne Cms Project 1 Shirne Cms 2024-11-21 6.5 Medium
An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php
CVE-2022-37122 1 Carel 4 Applica, Pcoweb Card, Pcoweb Card Firmware and 1 more 2024-11-21 7.5 High
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
CVE-2022-36890 1 Jenkins 1 Deployer Framework 2024-11-21 4.3 Medium
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.