The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
169 vulnerabilities with CWE-35
CVE-2024-47171
MEDIUM
agnai < 1.0.330 - Path Traversal and Arbitrary File Write via Image Upload
CVSS 4.3
CVE-2024-47170
MEDIUM
agnai < 1.0.330 - Path Traversal via JSON Storage
CVSS 4.3
CVE-2024-47169
HIGH
agnai < 1.0.330 - Unauthenticated Arbitrary File Write via Path Traversal
CVSS 8.8
CVE-2024-0067
MEDIUM
AXIS OS - Path Traversal via VAPIX API ledlimit.cgi
CVSS 4.3
CVE-2024-7608
MEDIUM
NX-EX-FX-AX-IVX-CMS - Path Traversal
CVSS 5.9
CVE-2024-45190
MEDIUM
Mage AI - Path Traversal via Pipeline Interaction Request
CVSS 6.5
CVE-2024-0113
HIGH
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC - Path Traversal via Web Support CGI URI
CVSS 7.5
CVE-2024-40505
CRITICAL
D-Link DAP-1650 <v.1.03 - Path Traversal
CVSS 9.3
CVE-2024-38706
MEDIUM
HasThemes HT Mega <2.5.7 - Path Traversal
CVSS 6.5
CVE-2024-39171
CRITICAL
phpvibe 11.0.3-11.0.46 - Path Traversal and Remote Code Execution via .htaccess and PNG File Upload
CVSS 9.8
CVE-2024-36991
HIGH
Splunk 9.0.0-9.0.9 - Path Traversal via /modules/messaging/ Endpoint
CVSS 7.5
CVE-2024-5481
MEDIUM
Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated Path Traversal via esc_dir Function
CVSS 6.8
CVE-2024-34191
MEDIUM
htmly 2.9.6 - Arbitrary File Deletion via delete_post() Function
CVSS 6.5
CVE-2024-2654
MEDIUM
WordPress File Manager <7.2.5 - Path Traversal
CVSS 6.8
CVE-2024-27901
HIGH
SAP Asset Accounting - Path Traversal
CVSS 7.2
CVE-2024-2863
MEDIUM
LG LED Assistant - Thumbnail Path Traversal File Upload
CVSS 5.3
CVE-2024-1886
LOW
LG webOS Signage - Path Traversal
CVSS 3.0
CVE-2023-7263
HIGH
Huawei home music system - Path Traversal
CVSS 7.3
CVE-2023-7300
HIGH
Huawei Home Music System - Path Traversal
CVSS 8.0
CVE-2023-41793
MEDIUM
Pandora FMS 700-775 - Path Traversal and Arbitrary File Write
CVSS 6.7
CVE-2023-5800
MEDIUM
AXIS OS < 11.8.61, 2020 < 9.80.55, 2022 < 10.12.220 - Authenticated RCE via VAPIX API
CVSS 5.4
CVE-2023-46690
HIGH
Delta Electronics InfraSuite Device Master <1.0.7 - Code Injection
CVSS 8.8
CVE-2023-5885
MEDIUM
Franklin Fueling Colibri Firmware - Unauthenticated Path Traversal
CVSS 6.5
CVE-2023-6252
HIGH
Chameleon Power - Path Traversal via getImage Parameter
CVSS 7.5
CVE-2023-21418
HIGH
AXIS OS < 6.50.5.15, < 11.7.57, < 8.40.35, < 9.80.49, < 10.12.213 - Path Traversal & File Deletion via VAPIX API
CVSS 7.1
Details
Vulnerabilities
169