The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.
108 vulnerabilities with CWE-24
CVE-2024-8409
MEDIUM
ABCD ABCD2 <2.2.0-beta-1 - Path Traversal
CVSS 4.3
CVE-2024-37403
MEDIUM
Ivanti Docs@work < 2.26.0 - Path Traversal
CVSS 5.5
CVE-2024-23657
HIGH
Nuxt < 1.3.9 - Path Traversal
CVSS 8.8
CVE-2024-6746
MEDIUM
NaiboWang EasySpider 0.6.2 - Path Traversal
CVSS 4.3
CVE-2024-4790
MEDIUM
Dedecms - Path Traversal
CVSS 4.3
CVE-2024-3686
MEDIUM
Dedecms - Path Traversal
CVSS 4.3
CVE-2024-3227
MEDIUM
Weaver E-office < 9.5 - Path Traversal
CVSS 4.7
CVE-2024-3218
MEDIUM
Shibang Communications IP Network Intercom Broadcasting System 1.0 ...
CVSS 5.4
CVE-2024-2825
MEDIUM
Lakernote Easyadmin < 2024-03-15 - Path Traversal
CVSS 6.3
CVE-2024-22079
HIGH
Elspec G5 <1.1.4.15 - Path Traversal
CVSS 7.5
CVE-2024-2564
MEDIUM
Pandax < 2024-03-10 - Path Traversal
CVSS 6.3
CVE-2024-2563
MEDIUM
Pandax < 2024-03-10 - Path Traversal
CVSS 5.4
CVE-2024-2318
MEDIUM
Zkteco Zkbio Media - Path Traversal
CVSS 4.3
CVE-2024-1459
MEDIUM
Redhat Undertow < 2.2.31.Final - Path Traversal
CVSS 5.3
CVE-2024-0989
MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Path Traversal
CVSS 5.4
CVE-2024-0882
MEDIUM
qwdigital LinkWechat 5.1.0 - Path Traversal
CVSS 4.3
CVE-2024-0465
LOW
code-projects Employee Profile Management System 1.0 - Path Traversal
CVSS 3.5
CVE-2024-0417
MEDIUM
Csdeshang Dsshop < 2.1.5 - Path Traversal
CVSS 5.4
CVE-2024-0416
MEDIUM
Csdeshang Dsmall < 5.0.3 - Path Traversal
CVSS 5.4
CVE-2024-0354
MEDIUM
Unknown-o Download-station < 1.1.8 - Path Traversal
CVSS 5.3
CVE-2024-0341
LOW
Inis < 2.0.1 - Path Traversal
CVSS 3.5
CVE-2023-53691
HIGH
Hikvision CSMP iSecure Center <2023-06-25 - Path Traversal
CVSS 8.3
CVE-2023-52076
HIGH
Atril Document Viewer <1.26.2 - Path Traversal
CVSS 8.5
CVE-2023-6699
CRITICAL
Wpcompress WP Compress < 6.10.33 - Path Traversal
CVSS 9.1
CVE-2023-7134
MEDIUM
Oretnom23 Medicine Tracker System - Path Traversal
CVSS 6.3
Details
Vulnerabilities
108