Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Medicine Tracker System CRITICAL 9.8
CVE-2023-7134

A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. …

No fix yet
Fix from $2,300 2023-12-28
Deepin Compressor HIGH 7.8
CVE-2023-50255

Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor th…

Fix: 5.12.21+
Fix from $1,950 2023-12-27
University Information Management System CRITICAL 9.8
CVE-2023-6190

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information …

Fix: 30.11.2023+
Fix from $2,300 2023-12-27
Hotel Booking Lite CRITICAL 9.8
CVE-2023-5991

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and a…

Fix: 4.8.5+
Fix from $2,300 2023-12-26
Wp Mail Log MEDIUM 6.5
CVE-2023-5672

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file i…

Fix: 1.1.3+
Fix from $1,600 2023-12-26
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-41760

An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the fi…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-41761

An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI…

No fix yet
Fix from $1,600 2023-12-25
Backup Migration CRITICAL 9.8
CVE-2023-6972

The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and '…

Fix: 1.4.0+
Fix from $2,300 2023-12-23
Gradio HIGH 7.5
CVE-2023-51449EPSS 28%

Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbit…

Fix: 4.11.0+
Fix from $1,950 2023-12-22
Mindsdb CRITICAL 9.1
CVE-2023-50731

MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` do…

Fix: 23.11.4.1+
Fix from $2,300 2023-12-22
Deepin Reader HIGH 7.8
CVE-2023-50254

Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw …

Fix: 6.0.7+
Fix from $1,950 2023-12-22
Kakadu Sdk HIGH 7.5
CVE-2023-6562

JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server …

Fix: after 8.4
Fix from $1,950 2023-12-20
Security Guardium Key Lifecycle Manager CRITICAL 9.1
CVE-2023-47702

IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a special…

Fix: 4.2.0.2+
Fix from $2,300 2023-12-20
Edgeaggregator HIGH 7.2
CVE-2023-38126EPSS 71%

Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…

Mitigation only
Fix from $1,950 2023-12-19
Quttera Web Malware Scanner HIGH 7.2
CVE-2023-6222

IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin r…

Fix: 3.4.2.1+
Fix from $1,950 2023-12-18
Mq Appliance HIGH 7.5
CVE-2023-46177

IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

Patch available
Fix from $1,950 2023-12-18
Ansible Automation Platform MEDIUM 6.3
CVE-2023-5115

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make …

Mitigation only
Fix from $1,600 2023-12-18
Kuiper MEDIUM 5.9
CVE-2023-6908

A vulnerability, which was classified as problematic, was found in DFIRKuiper Kuiper 2.3.4. This affects the function unzip_file of the file kuiper/a…

Patch available
Fix from $1,600 2023-12-18
Dashmachine CRITICAL 9.1
CVE-2023-6900

A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functional…

No fix yet
Fix from $2,300 2023-12-17
Intercom Broadcast System HIGH 7.5
CVE-2023-6893EPSS 70%

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue…

Fix: 4.1.0+
Fix from $1,950 2023-12-17
Mw Wp Form CRITICAL 9.8
CVE-2023-6559

The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin n…

Fix: 5.0.4+
Fix from $2,300 2023-12-16
Edge HIGH 7.5
CVE-2021-42797

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Window…

Fix: 2020+
Fix from $1,950 2023-12-16
Bazarr HIGH 7.5
CVE-2023-50264

Bazarr manages and downloads subtitles. Prior to 1.3.1, Bazarr contains an arbitrary file read in /system/backup/download/ endpoint in bazarr/app/ui.…

Fix: 1.3.1+
Fix from $1,950 2023-12-15
Bazarr HIGH 7.5
CVE-2023-50265

Bazarr manages and downloads subtitles. Prior to 1.3.1, the /api/swaggerui/static endpoint in bazarr/app/ui.py does not validate the user-controlled …

Fix: 1.3.1+
Fix from $1,950 2023-12-15
Easylog Web\+ Firmware HIGH 7.5
CVE-2023-48389

Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this…

Mitigation only
Fix from $1,950 2023-12-15
Mail Sqr Expert MEDIUM 6.5
CVE-2023-48381

Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remo…

Fix: 230330+
Fix from $1,600 2023-12-15
Mail Sqr Expert MEDIUM 6.5
CVE-2023-48382

Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthe…

Fix: 230330+
Fix from $1,600 2023-12-15
Mail Sqr Expert HIGH 7.5
CVE-2023-48378

Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit th…

Fix: after 230330
Fix from $1,950 2023-12-15
Omicard Edm HIGH 7.5
CVE-2023-48373

ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can…

Mitigation only
Fix from $1,950 2023-12-15
Mlflow HIGH 8.1
CVE-2023-6831

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

Fix: 2.9.2+
Fix from $1,950 2023-12-15