| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43789 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of… | ||
| CVE-2024-43363 | Hig | 0.50 | 7.2 | 0.36 | Oct 7, 2024 | Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps… | ||
| CVE-2024-43362 | Hig | 0.50 | 7.3 | 0.36 | Oct 7, 2024 | Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and… | ||
| CVE-2024-45293 | Hig | 0.42 | 7.5 | 0.03 | Oct 7, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload… | ||
| CVE-2024-31449 | Hig | 0.00 | 7.0 | 0.04 | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis… | ||
| CVE-2024-47975 | Hig | 0.46 | 7.0 | 0.00 | Oct 7, 2024 | Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service. | ||
| CVE-2024-47559 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2024-47558 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2024-47557 | Hig | 0.54 | 8.3 | 0.01 | Oct 7, 2024 | Pre-Auth RCE via Path Traversal | ||
| CVE-2024-47556 | Hig | 0.54 | 8.3 | 0.01 | Oct 7, 2024 | Pre-Auth RCE via Path Traversal | ||
| CVE-2024-44068 | Hig | 0.53 | 8.1 | 0.01 | Oct 7, 2024 | An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation. | ||
| CVE-2024-47555 | Hig | 0.54 | 8.3 | 0.00 | Oct 7, 2024 | Missing Authentication - User & System Configuration | ||
| CVE-2024-27458 | Hig | 0.57 | 8.8 | 0.00 | Oct 7, 2024 | A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support. | ||
| CVE-2024-9570 | Hig | 0.57 | 8.8 | 0.03 | Oct 7, 2024 | A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched… | ||
| CVE-2024-46278 | Hig | 0.58 | 8.4 | 0.03 | Oct 7, 2024 | Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console. | ||
| CVE-2024-46041 | Hig | 0.57 | 8.8 | 0.00 | Oct 7, 2024 | IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay. | ||
| CVE-2024-9576 | Hig | 0.46 | 7.0 | 0.00 | Oct 7, 2024 | Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script. | ||
| CVE-2024-9569 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2024 | A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file /goform/formEasySetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be… | ||
| CVE-2024-9568 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2024 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely.… | ||
| CVE-2023-6362 | Hig | 0.47 | 7.3 | 0.00 | Oct 7, 2024 | A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument. | ||
| CVE-2023-6361 | Hig | 0.47 | 7.3 | 0.00 | Oct 7, 2024 | A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument. | ||
| CVE-2024-9567 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2024 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the function formAdvFirewall of the file /goform/formAdvFirewall. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated… | ||
| CVE-2024-9566 | Hig | 0.57 | 8.8 | 0.02 | Oct 7, 2024 | A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely.… | ||
| CVE-2024-43047 | Hig | 0.63 | 7.8 | 0.01 | KEV | Oct 7, 2024 | Memory corruption while maintaining memory maps of HLOS memory. | |
| CVE-2024-38399 | Hig | 0.55 | 8.4 | 0.00 | Oct 7, 2024 | Memory corruption while processing user packets to generate page faults. | ||
| CVE-2024-38397 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing probe response and assoc response frame. | ||
| CVE-2024-33073 | Hig | 0.53 | 8.2 | 0.00 | Oct 7, 2024 | Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | ||
| CVE-2024-33071 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0. | ||
| CVE-2024-33070 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-33069 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host. | ||
| CVE-2024-33065 | Hig | 0.55 | 8.4 | 0.00 | Oct 7, 2024 | Memory corruption while taking snapshot when an offset variable is set by camera driver. | ||
| CVE-2024-33064 | Hig | 0.53 | 8.2 | 0.00 | Oct 7, 2024 | Information disclosure while parsing the multiple MBSSID IEs from the beacon. | ||
| CVE-2024-33049 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. | ||
| CVE-2024-23369 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. | ||
| CVE-2024-21455 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver. | ||
| CVE-2024-47335 | Hig | 0.49 | 7.6 | 0.00 | Oct 7, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.13.11. | ||
| CVE-2024-20094 | Hig | 0.49 | 7.5 | 0.01 | Oct 7, 2024 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535. | ||
| CVE-2024-20092 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1700. | ||
| CVE-2024-9565 | Hig | 0.57 | 8.8 | 0.02 | Oct 7, 2024 | A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be… | ||
| CVE-2024-9564 | Hig | 0.57 | 8.8 | 0.02 | Oct 7, 2024 | A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the… | ||
| CVE-2024-9563 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2024 | A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. The manipulation of the argument webpage leads to buffer overflow. The attack may be… | ||
| CVE-2024-9562 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been… | ||
| CVE-2024-9561 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The… | ||
| CVE-2024-9559 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the attack… | ||
| CVE-2024-9558 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation of the argument webpage leads to buffer overflow. The attack may be initiated remotely. The… | ||
| CVE-2024-9557 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The manipulation of the argument webpage leads to buffer overflow. The attack can be initiated… | ||
| CVE-2024-9556 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the… | ||
| CVE-2024-9555 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2024 | A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the file /goform/formSetEasy_Wizard. The manipulation of the argument curTime leads to buffer overflow. The attack may… | ||
| CVE-2024-47338 | Hig | 0.55 | 8.5 | 0.00 | Oct 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through <= 1.3. | ||
| CVE-2024-45248 | Hig | 0.49 | 7.5 | 0.01 | Oct 6, 2024 | Multi-DNC – CWE-35: Path Traversal: '.../...//' |
- risk 0.49cvss 7.5epss 0.00
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of…
- risk 0.50cvss 7.2epss 0.36
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps…
- risk 0.50cvss 7.3epss 0.36
Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and…
- risk 0.42cvss 7.5epss 0.03
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload…
- risk 0.00cvss 7.0epss 0.04
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis…
- risk 0.46cvss 7.0epss 0.00
Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service.
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.54cvss 8.3epss 0.01
Pre-Auth RCE via Path Traversal
- risk 0.54cvss 8.3epss 0.01
Pre-Auth RCE via Path Traversal
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.
- risk 0.54cvss 8.3epss 0.00
Missing Authentication - User & System Configuration
- risk 0.57cvss 8.8epss 0.00
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.
- risk 0.57cvss 8.8epss 0.03
A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched…
- risk 0.58cvss 8.4epss 0.03
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
- risk 0.57cvss 8.8epss 0.00
IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.
- risk 0.46cvss 7.0epss 0.00
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file /goform/formEasySetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be…
- risk 0.57cvss 8.8epss 0.01
A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely.…
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler (SEH) registers. This could allow attackers to execute arbitrary code via a long filename argument.
- risk 0.57cvss 8.8epss 0.01
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the function formAdvFirewall of the file /goform/formAdvFirewall. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated…
- risk 0.57cvss 8.8epss 0.02
A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely.…
- risk 0.63cvss 7.8epss 0.01
Memory corruption while maintaining memory maps of HLOS memory.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing user packets to generate page faults.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing probe response and assoc response frame.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while taking snapshot when an offset variable is set by camera driver.
- risk 0.53cvss 8.2epss 0.00
Information disclosure while parsing the multiple MBSSID IEs from the beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
- risk 0.49cvss 7.6epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.13.11.
- risk 0.49cvss 7.5epss 0.01
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535.
- risk 0.51cvss 7.8epss 0.00
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1700.
- risk 0.57cvss 8.8epss 0.02
A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be…
- risk 0.57cvss 8.8epss 0.02
A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the…
- risk 0.57cvss 8.8epss 0.01
A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. The manipulation of the argument webpage leads to buffer overflow. The attack may be…
- risk 0.57cvss 8.8epss 0.01
A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been…
- risk 0.57cvss 8.8epss 0.01
A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the attack…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation of the argument webpage leads to buffer overflow. The attack may be initiated remotely. The…
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The manipulation of the argument webpage leads to buffer overflow. The attack can be initiated…
- risk 0.57cvss 8.8epss 0.01
A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the…
- risk 0.57cvss 8.8epss 0.01
A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the file /goform/formSetEasy_Wizard. The manipulation of the argument curTime leads to buffer overflow. The attack may…
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through <= 1.3.
- risk 0.49cvss 7.5epss 0.01
Multi-DNC – CWE-35: Path Traversal: '.../...//'