Skip to main content

CWE archive

CWE-36 CVEs

Programmatic archive

131 CVEs tagged with CWE-3615 Critical, 62 High, 50 Medium, 4 Low, 0 Unrated.

CVE-2024-10811

Published Jan 14, 2025

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensi…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2024-56321

Published Jan 3, 2025

GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potent…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-12646

Published Dec 16, 2024

The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the ta…

CVSS 8.1 · High

CVE-2024-12644

Published Dec 16, 2024

The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target web…

CVSS 7.1 · High

CVE-2024-12643

Published Dec 16, 2024

The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the tar…

CVSS 8.1 · High

CVE-2024-11978

Published Nov 29, 2024

DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

CVSS 7.5 · High

CVE-2024-10651

Published Nov 1, 2024

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileg…

CVSS 4.9 · Medium

CVE-2024-47883

Published Oct 24, 2024

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-9924

Published Oct 14, 2024

The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary syst…

CVSS 9.8 · Critical

CVE-2024-45291

Published Oct 7, 2024

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. Whe…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45290

Published Oct 7, 2024

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8497

Published Sep 25, 2024

Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

CVSS 8.7 · High

CVE-2024-8778

Published Sep 16, 2024

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7323

Published Aug 2, 2024

Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28806

Published Jul 29, 2024

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20401

Published Jul 17, 2024

A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files o…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2024-6250

Published Jun 27, 2024

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33620

Published Jun 18, 2024

Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive inform…

CVSS 8.6 · High

CVE-2024-4881

Published Jun 6, 2024

A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2548

Published Jun 6, 2024

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41830

Published May 3, 2024

An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.

CVSS 6.5 · Medium
Showing 76-100 of 131 CVEsPage 4 of 6