Vulnerabilities (CVE)

Filtered by CWE-22
Total 6174 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30804 1 Elitecms 1 Elite Cms 2023-08-08 5.5 MEDIUM 6.5 MEDIUM
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
CVE-2022-31475 1 Givewp 1 Givewp 2023-08-08 N/A 4.9 MEDIUM
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
CVE-2022-1128 2 Google, Microsoft 2 Chrome, Windows 2023-08-08 N/A 6.5 MEDIUM
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
CVE-2022-28741 1 Aenrich 1 A\+hrd 2023-08-08 N/A 8.1 HIGH
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
CVE-2022-36687 1 Ingredient Stock Management System Project 1 Ingredient Stock Management System 2023-08-08 N/A 6.5 MEDIUM
Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
CVE-2022-38638 1 Casbin 1 Casdoor 2023-08-08 N/A 9.1 CRITICAL
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CVE-2022-38258 1 Dlink 2 Dir-819, Dir-819 Firmware 2023-08-08 N/A 8.1 HIGH
A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server information via manipulation of the getpage parameter in a crafted web request.
CVE-2022-3060 1 Gitlab 1 Gitlab 2023-08-08 N/A 7.3 HIGH
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests
CVE-2022-30508 1 Dedecms 1 Dedecms 2023-08-08 5.5 MEDIUM 6.5 MEDIUM
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
CVE-2022-37042 1 Zimbra 1 Collaboration 2023-08-08 N/A 9.8 CRITICAL
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
CVE-2022-42977 1 Atlassian 1 Confluence Data Center 2023-08-08 N/A 7.5 HIGH
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be downloaded.
CVE-2022-35235 1 Xplodedthemes 1 Wpide - File Manager \& Code Editor 2023-08-08 N/A 4.9 MEDIUM
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-44280 1 Automotive Shop Management System Project 1 Automotive Shop Management System 2023-08-08 N/A 6.5 MEDIUM
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.
CVE-2021-23484 1 Zip-local Project 1 Zip-local 2023-08-08 7.5 HIGH 9.8 CRITICAL
The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.
CVE-2022-47945 1 Thinkphp 1 Thinkphp 2023-08-08 N/A 9.8 CRITICAL
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.
CVE-2021-22005 1 Vmware 2 Cloud Foundation, Vcenter Server 2023-08-08 7.5 HIGH 9.8 CRITICAL
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
CVE-2022-25856 1 Argo Events Project 1 Argo Events 2023-08-08 5.0 MEDIUM 7.5 HIGH
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...
CVE-2022-32409 1 Softwarepublico 1 I3geo 2023-08-08 N/A 9.8 CRITICAL
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
CVE-2022-26019 1 Netgate 2 Pfsense, Pfsense Plus 2023-08-08 8.5 HIGH 8.8 HIGH
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.
CVE-2022-27925 1 Zimbra 1 Collaboration 2023-08-08 6.5 MEDIUM 7.2 HIGH
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.