Vulnerabilities (CVE)

Filtered by CWE-22
Total 10261 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46987 1 Tuzitio 1 Camaleon Cms 2026-06-17 N/A 7.7 HIGH
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions). This issue may lead to Information Disclosure. This issue has been addressed in release version 2.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-46986 1 Tuzitio 1 Camaleon Cms 2026-06-17 N/A 9.9 CRITICAL
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the underlying filesystem). E.g. This can lead to a delayed remote code execution in case an attacker is able to write a Ruby file into the config/initializers/ subfolder of the Ruby on Rails application. This issue has been addressed in release version 2.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-46977 1 Openc3 1 Cosmos 2026-06-17 N/A 6.5 MEDIUM
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0.
CVE-2024-46954 1 Artifex 1 Ghostscript 2026-06-17 N/A 7.8 HIGH
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
CVE-2024-46939 2026-06-17 N/A N/A
The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files
CVE-2024-46909 1 Progress 1 Whatsup Gold 2026-06-17 N/A 9.8 CRITICAL
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
CVE-2024-46898 1 Ss-proj 1 Shirasagi 2026-06-17 N/A 7.5 HIGH
SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.
CVE-2024-46888 1 Siemens 1 Sinec Ins 2026-06-17 N/A 9.9 CRITICAL
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary code execution on the device.
CVE-2024-46664 1 Fortinet 1 Fortirecorder 2026-06-17 N/A 5.5 MEDIUM
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
CVE-2024-46649 1 Enms 1 Enms 2026-06-17 N/A 7.5 HIGH
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
CVE-2024-46648 1 Enms 1 Enms 2026-06-17 N/A 7.5 HIGH
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
CVE-2024-46647 1 Enms 1 Enms 2026-06-17 N/A 6.5 MEDIUM
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
CVE-2024-46646 1 Enms 1 Enms 2026-06-17 N/A 6.5 MEDIUM
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
CVE-2024-46645 1 Enms 1 Enms 2026-06-17 N/A 7.5 HIGH
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
CVE-2024-46644 1 Enms 1 Enms 2026-06-17 N/A 6.5 MEDIUM
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
CVE-2024-46376 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.
CVE-2024-46375 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.
CVE-2024-46327 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 5.7 MEDIUM
An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.
CVE-2024-46212 1 Redaxo 1 Redaxo 2026-06-17 N/A 4.9 MEDIUM
An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.
CVE-2024-45842 2 Sharp, Toshibatec 640 Bp-30c25, Bp-30c25 Firmware, Bp-30c25t and 637 more 2026-06-17 N/A 5.3 MEDIUM
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.