Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 20 of 81 CVEs matching "Versa" · HIGH

CVE-2024-13159KEV
High

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

IvantiEPSS 94.2%
CVE-2024-13160KEV
High

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

IvantiEPSS 93.5%
CVE-2024-13161KEV
High

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

IvantiEPSS 92.6%
CVE-2024-4885KEV
High

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

ProgressEPSS 94.3%
CVE-2024-57727KEV
High

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

SimpleHelp EPSS 93.7%
CVE-2024-41713KEV
High

Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

MitelEPSS 93.9%
CVE-2024-55550KEV
High

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

MitelEPSS 14.9%
CVE-2024-11667KEV
High

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

ZyxelEPSS 34.2%
CVE-2021-26086KEV
High

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

AtlassianEPSS 94.2%
CVE-2019-16278KEV
High

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

NostromoEPSS 94.4%
CVE-2024-8963KEV
High

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.

IvantiEPSS 94.2%
CVE-2021-20124KEV
High

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

DrayTekEPSS 94.1%
CVE-2021-20123KEV
High

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

DrayTekEPSS 94.0%
CVE-2024-7262KEV
High

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

KingsoftEPSS 15.9%
CVE-2024-39717KEV
High

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.

VersaEPSS 4.6%
CVE-2024-23897KEV
High

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

JenkinsEPSS 94.5%
CVE-2024-32113KEV
High

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.

ApacheEPSS 94.0%
CVE-2024-28995KEV
High

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

SolarWindsEPSS 94.4%
CVE-2023-41266KEV
High

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

QlikEPSS 94.3%
CVE-2023-47246KEV
High

SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.

SysAidEPSS 94.3%