CVE-2024-49253

CVSS v3 Score
8.6
High

Vulnerability Description

Relative Path Traversal vulnerability in James Park Analyse Uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through 0.5.

CVSS:8.6(High)

ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and ...

CWE-232021
CVSS:8.7(High)

Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CWE-232023
CVSS:8.8(High)

Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

CWE-232017
CVSS:8.8(High)

A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not hav...

CWE-232017
CVSS:8.8(High)

DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.

CWE-232018
CVSS:8.8(High)

Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.

CWE-232019