Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Asterisk HIGH 7.5
CVE-2023-49294EPSS 46%

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certi…

Fix: 18.20.1 / 20.5.1+
Fix from $1,950 2023-12-14
Solutions Enabler Virtual Appliance HIGH 7.5
CVE-2023-48660

Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerabil…

Fix: 9.2.4.5 / 9.2.4.7+
Fix from $1,950 2023-12-14
Powerprotect Data Protection MEDIUM 6.7
CVE-2023-44278

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high priv…

Fix: 2.7.6 / 6.2.1.110+
Fix from $1,600 2023-12-14
Easy Ups Online Monitoring Software HIGH 7.1
CVE-2023-6407

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletio…

Fix: 2.6-ga-01-23248+
Fix from $1,950 2023-12-14
Meeting Software Development Kit HIGH 8.8
CVE-2023-43586

Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct …

Fix: 5.14.14 / 5.15.12+
Fix from $1,950 2023-12-13
Audiobookshelf MEDIUM 6.5
CVE-2023-47624

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to …

Fix: after 2.4.3
Fix from $1,600 2023-12-13
Fortiwan HIGH 8.8
CVE-2023-44251

** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet Fo…

Mitigation only
Fix from $1,950 2023-12-13
Mlflow HIGH 8.8
CVE-2023-6753

Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

Fix: 2.9.2+
Fix from $1,950 2023-12-13
Umbraco Cms MEDIUM 6.5
CVE-2023-49089

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users …

Fix: 8.18.10 / 10.8.1+
Fix from $1,600 2023-12-12
Hl7 Fhir Core HIGH 7.5
CVE-2023-28465

The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain dire…

Fix: 5.6.106+
Fix from $1,950 2023-12-12
Gl Ar300m Firmware HIGH 7.5
CVE-2023-46455EPSS 47%

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file …

Mitigation only
Fix from $1,950 2023-12-12
Mattermost Server HIGH 8.8
CVE-2023-45316

Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing a…

Fix: after 9.2.1
Fix from $1,950 2023-12-12
Master Data Governance MEDIUM 5.3
CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus …

Mitigation only
Fix from $1,600 2023-12-12
Cryptospike MEDIUM 6.5
CVE-2023-36654

Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host serv…

No fix yet
Fix from $1,600 2023-12-12
Jfinalcms HIGH 7.5
CVE-2023-50449

JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.

No fix yet
Fix from $1,950 2023-12-10
Evershop MEDIUM 5.3
CVE-2023-46493

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted…

Mitigation only
Fix from $1,600 2023-12-08
Evershop HIGH 8.3
CVE-2023-46496

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted…

Mitigation only
Fix from $1,950 2023-12-08
Evershop MEDIUM 5.4
CVE-2023-46497

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted…

Mitigation only
Fix from $1,600 2023-12-08
Richdocumentscode HIGH 7.2
CVE-2023-49788

Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the B…

Fix: 23.5.602+
Fix from $1,950 2023-12-08
Gladys Assistant MEDIUM 6.5
CVE-2023-47440

Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticat…

Fix: 4.30.0+
Fix from $1,600 2023-12-07
M11sdv 4c Ln4f Firmware HIGH 7.5
CVE-2023-33411

A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 b…

Fix: after 3.17.02
Fix from $1,950 2023-12-07
Etcd Browser HIGH 7.5
CVE-2023-46307

An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while…

Mitigation only
Fix from $1,950 2023-12-07
Mattermost Server CRITICAL 9.8
CVE-2023-6458

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver…

Fix: 7.8.14 / 8.1.5+
Fix from $2,300 2023-12-06
Frontend File Manager Plugin MEDIUM 6.5
CVE-2023-5105

The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and d…

Fix: 22.6+
Fix from $1,600 2023-12-04
Dm5500 Firmware MEDIUM 6.5
CVE-2023-44306

Dell DM5500 contains a path traversal vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerabi…

Fix: after 5.14.0.0
Fix from $1,600 2023-12-04
Rakrak Document Plus HIGH 8.8
CVE-2023-49108

Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, …

Fix: 6.1.1.3a+
Fix from $1,950 2023-12-04
Online Accounting System HIGH 7.5
CVE-2018-25094

A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown pro…

Fix: 2.0.0+
Fix from $1,950 2023-12-03
Infrasuite Device Master HIGH 7.5
CVE-2023-47279

In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information th…

Mitigation only
Fix from $1,950 2023-11-30
Tiles HIGH 7.5
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML…

Mitigation only
Fix from $1,950 2023-11-30
Infrasuite Device Master HIGH 8.8
CVE-2023-46690

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the fil…

Mitigation only
Fix from $1,950 2023-11-30