Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Financial Calculator MEDIUM 5.3
CVE-2021-35975

Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows…

Fix: after 3.9.256.777
Fix from $1,600 2023-11-30
Tiff Server MEDIUM 5.3
CVE-2023-6352

The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Informatio…

No fix yet
Fix from $1,600 2023-11-30
Phpmemcachedadmin CRITICAL 9.1
CVE-2023-6026

A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete…

Mitigation only
Fix from $2,300 2023-11-30
Gl Ax1800 Firmware HIGH 8.8
CVE-2023-47464EPSS 23%

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API…

Fix: 4.5.0+
Fix from $1,950 2023-11-30
Dreamer Cms CRITICAL 9.1
CVE-2023-46886

Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template f…

Fix: 4.0.1+
Fix from $2,300 2023-11-29
Ureport HIGH 7.5
CVE-2023-48848

An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path.

Mitigation only
Fix from $1,950 2023-11-28
Chamilo CRITICAL 9.8
CVE-2023-3533

Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attac…

Fix: after 1.11.20
Fix from $2,300 2023-11-28
Colibri Firmware MEDIUM 6.5
CVE-2023-5885

The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.

Mitigation only
Fix from $1,600 2023-11-27
Oroplatform CRITICAL 9.8
CVE-2022-41951

OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications easier and faster. Path Travers…

Fix: 5.0.9+
Fix from $2,300 2023-11-27
Udp CRITICAL 9.8
CVE-2023-42000

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthentic…

Fix: 9.2+
Fix from $2,300 2023-11-27
Application And Change Control HIGH 7.2
CVE-2023-5607

An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers…

Fix: 8.4.0+
Fix from $1,950 2023-11-27
Jimureport CRITICAL 9.8
CVE-2023-6307

A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of t…

Fix: after 1.6.1
Fix from $2,300 2023-11-27
Neu Ipb210 28 Firmware HIGH 7.5
CVE-2023-6118

Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal. This issue affects IP Camera: before b1130.1.0.1.

Mitigation only
Fix from $1,950 2023-11-23
Slmail MEDIUM 6.5
CVE-2023-4593

Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a…

Mitigation only
Fix from $1,600 2023-11-23
Vigor2960 Firmware HIGH 8.1
CVE-2023-6265

** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'op…

No fix yet
Fix from $1,950 2023-11-22
Mprivacy Tools MEDIUM 6.5
CVE-2023-47251

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authentica…

Fix: 2.0.406g / 4.1.2-1+
Fix from $1,600 2023-11-22
Jeecg Boot MEDIUM 6.5
CVE-2023-47467

Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory st…

Mitigation only
Fix from $1,600 2023-11-22
Headwind Mdm MEDIUM 5.4
CVE-2023-47313

Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploaded temporary file to the file …

No fix yet
Fix from $1,600 2023-11-22
Lifterlms MEDIUM 6.7
CVE-2023-6160

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 …

Fix: after 7.4.2
Fix from $1,600 2023-11-22
Chameleon Power HIGH 7.5
CVE-2023-6252

Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read fi…

Mitigation only
Fix from $1,950 2023-11-22
Torchserve MEDIUM 5.3
CVE-2023-48299

TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to version 0.9.0, using the model/work…

Fix: 0.9.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-6209

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specifi…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Axis Os HIGH 7.1
CVE-2023-21417

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks…

Fix: 9.80.49 / 10.12.208+
Fix from $1,950 2023-11-21
Axis Os HIGH 7.1
CVE-2023-21418

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allo…

Fix: 6.50.5.15 / 8.40.35+
Fix from $1,950 2023-11-21
Opensis HIGH 7.5
CVE-2023-38879

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability …

Mitigation only
Fix from $1,950 2023-11-20
Terra Master HIGH 7.5
CVE-2023-48185

Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET re…

Fix: after 2.295
Fix from $1,950 2023-11-17
Robohelp Server HIGH 7.2
CVE-2023-22273

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Fix: after 11.4
Fix from $1,950 2023-11-17
Cubecart MEDIUM 6.5
CVE-2023-42428

Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete direct…

Fix: 6.5.3+
Fix from $1,600 2023-11-17
Sonice Retour HIGH 7.5
CVE-2023-45382

In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information with…

Fix: after 2.1.0
Fix from $1,950 2023-11-17
Ray HIGH 7.5
CVE-2023-6021EPSS 37%

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maint…

No fix yet
Fix from $1,950 2023-11-16