Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Lif Auth Server HIGH 7.5
CVE-2023-49801

Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` an…

Fix: 1.4.0+
Fix from $1,950 2024-01-12
Femitter Server HIGH 7.5
CVE-2010-10011

A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation le…

No fix yet
Fix from $1,950 2024-01-12
Triton Inference Server HIGH 8.8
CVE-2023-31036

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --m…

Fix: 2.40+
Fix from $1,950 2024-01-12
Go Git CRITICAL 9.8
CVE-2023-49569

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files acro…

Fix: 5.11.0+
Fix from $2,300 2024-01-12
Import And Export Users And Customers HIGH 7.2
CVE-2023-6583

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via …

Fix: after 1.24.2
Fix from $1,950 2024-01-11
Backwpup HIGH 8.7
CVE-2023-5504

The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows a…

Fix: after 4.0.1
Fix from $1,950 2024-01-11
Wp Compress HIGH 7.5
CVE-2023-6699

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.3…

Fix: after 6.10.33
Fix from $1,950 2024-01-11
Flir Ax8 Firmware HIGH 7.5
CVE-2023-51127

FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerabil…

Mitigation only
Fix from $1,950 2024-01-10
Device Manager HIGH 7.2
CVE-2023-50916

Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a U…

Fix: 3.1.1213.0+
Fix from $1,950 2024-01-10
Fortivoice MEDIUM 6.5
CVE-2023-37932

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and be…

Fix: 6.4.8+
Fix from $1,600 2024-01-10
Nexo Os MEDIUM 6.5
CVE-2023-48249

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application O…

Fix: after 1500-sp2
Fix from $1,600 2024-01-10
Nexo Os MEDIUM 6.5
CVE-2023-48246

The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root…

Fix: after 1500-sp2
Fix from $1,600 2024-01-10
Nexo Os MEDIUM 6.5
CVE-2023-48242

The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application…

Fix: after 1500-sp2
Fix from $1,600 2024-01-10
Nexo Os HIGH 8.8
CVE-2023-48243

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”)…

Fix: after 1500-sp2
Fix from $1,950 2024-01-10
Download Station HIGH 7.5
CVE-2024-0354

A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processi…

Fix: after 1.1.8
Fix from $1,950 2024-01-10
Inis HIGH 7.5
CVE-2024-0341

A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/cont…

Fix: after 2.0.1
Fix from $1,950 2024-01-09
Pyload HIGH 8.8
CVE-2023-47890

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

Mitigation only
Fix from $1,950 2024-01-08
Manageengine Firewall Analyzer HIGH 8.6
CVE-2023-47211EPSS 47%

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can le…

Fix: 12.7+
Fix from $1,950 2024-01-08
Iodine HIGH 7.5
CVE-2024-22050

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public fold…

Fix: after 0.7.33
Fix from $1,950 2024-01-04
S Cms MEDIUM 6.5
CVE-2023-29962

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

No fix yet
Fix from $1,600 2024-01-04
Android MEDIUM 5.5
CVE-2024-20804

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in A…

Fix: 14.5.00.21+
Fix from $1,600 2024-01-04
Android MEDIUM 5.5
CVE-2024-20805

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Andr…

Fix: 14.5.00.21+
Fix from $1,600 2024-01-04
Apktool HIGH 7.8
CVE-2024-21633

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to the…

Fix: 2.9.2+
Fix from $1,950 2024-01-03
Soc Fl9600 Firstlane Firmware HIGH 7.5
CVE-2023-37607

Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.…

No fix yet
Fix from $1,950 2024-01-03
Ifair HIGH 7.5
CVE-2023-47473

Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted …

Fix: after 23.8_ad0
Fix from $1,950 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45722

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is …

Mitigation only
Fix from $2,300 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45723

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate …

Mitigation only
Fix from $2,300 2024-01-03
Zxcloud Irai HIGH 7.8
CVE-2023-41780

There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker co…

Fix: 7.23.32+
Fix from $1,950 2024-01-03
Mattermost HIGH 8.8
CVE-2023-7114

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

Fix: 2.10.1+
Fix from $1,950 2023-12-29
Winter MEDIUM 5.4
CVE-2023-52085EPSS 30%

Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value…

Fix: 1.2.4+
Fix from $1,600 2023-12-29