Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Modeldb HIGH 7.5
CVE-2023-6023

An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.

No fix yet
Fix from $1,950 2023-11-16
Mlflow HIGH 7.5
CVE-2023-6015

MLflow allowed arbitrary files to be PUT onto the server.

Fix: 2.8.1+
Fix from $1,950 2023-11-16
Mleap CRITICAL 9.8
CVE-2023-5245

FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intend…

Patch available
Fix from $2,300 2023-11-15
Reactor Netty HIGH 7.5
CVE-2023-34062

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a speciall…

Fix: 1.0.39 / 1.1.13+
Fix from $1,950 2023-11-15
Galaxy Vl Firmware MEDIUM 5.3
CVE-2023-6032

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumerat…

Mitigation only
Fix from $1,600 2023-11-15
Ansible Automation Platform MEDIUM 6.5
CVE-2023-5189

A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy …

No fix yet
Fix from $1,600 2023-11-14
Audio Install Package HIGH 7.8
CVE-2023-33878

Path transversal in some Intel(R) NUC P14E Laptop Element Audio Install Package software before version 156 for Windows may allow an authenticated us…

Fix: 1.0.0.156+
Fix from $1,950 2023-11-14
Usb Type C Power Delivery Controller HIGH 7.3
CVE-2023-32655

Path transversal in some Intel(R) NUC Kits & Mini PCs - NUC8i7HVK & NUC8HNK USB Type C power delivery controller installatio software before version …

Fix: 1.0.10.3+
Fix from $1,950 2023-11-14
Nuc Uniwill Service Driver HIGH 7.3
CVE-2023-32278

Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installati…

Fix: 1.0.1.7+
Fix from $1,950 2023-11-14
Advisor HIGH 7.8
CVE-2023-24592

Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable e…

Fix: 2023.1+
Fix from $1,950 2023-11-14
Hdmi Firmware HIGH 7.8
CVE-2022-27229

Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authe…

Fix: 1.79.1.1+
Fix from $1,950 2023-11-14
Gibbon HIGH 7.2
CVE-2023-45880

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The…

Fix: after 25.0.00
Fix from $1,950 2023-11-14
Sysaid CRITICAL 9.8
CVE-2023-47246 KEVEPSS 99%

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as…

Fix: 23.3.36+
Fix from $2,300 2023-11-10
Go HIGH 7.5
CVE-2023-45283

The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equiv…

Fix: 1.20.11 / 1.21.4+
Fix from $1,950 2023-11-09
Network Configuration Manager HIGH 8.8
CVE-2023-40055

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-leve…

Fix: after 2023.4
Fix from $1,950 2023-11-09
Network Configuration Manager HIGH 8.8
CVE-2023-40054

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-leve…

Fix: after 2023.4
Fix from $1,950 2023-11-09
Bgs5 Firmware HIGH 7.1
CVE-2023-47613

A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion E…

Mitigation only
Fix from $1,950 2023-11-09
Couchbase Server HIGH 7.5
CVE-2023-36667

Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

Fix: 7.1.5+
Fix from $1,950 2023-11-08
Squidex HIGH 7.2
CVE-2023-46253

Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the back…

No fix yet
Fix from $1,950 2023-11-07
Awesome Support HIGH 8.1
CVE-2023-5355

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter …

Fix: 6.1.5+
Fix from $1,950 2023-11-06
Music Station HIGH 7.5
CVE-2023-39299

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of u…

Fix: 4.8.11 / 5.1.16+
Fix from $1,950 2023-11-03
Storage CRITICAL 9.8
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…

Fix: 4.17.12 / 4.18.8+
Fix from $2,300 2023-11-03
Mobile Device Manager HIGH 7.5
CVE-2023-41344

NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl…

Mitigation only
Fix from $1,950 2023-11-03
Tronclass Ilearn MEDIUM 6.5
CVE-2023-41356

NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl…

Mitigation only
Fix from $1,600 2023-11-03
D Copia253mf Plus Firmware HIGH 7.5
CVE-2023-34260EPSS 73%

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a dire…

Fix: after 2vg_s000.002.561
Fix from $1,950 2023-11-03
Secure Firewall Management Center HIGH 8.8
CVE-2023-20220

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remo…

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
Network Configuration Manager HIGH 8.8
CVE-2023-33226

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-leve…

Fix: 2023.4+
Fix from $1,950 2023-11-01
Network Configuration Manager HIGH 8.8
CVE-2023-33227

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level …

Fix: 2023.4+
Fix from $1,950 2023-11-01
Modular Advanced Control For Hvdc MEDIUM 6.5
CVE-2023-2621

The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This v…

Fix: 7.17.0.0+
Fix from $1,600 2023-11-01
Fogproject MEDIUM 5.3
CVE-2023-46237

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited en…

Fix: 1.5.10+
Fix from $1,600 2023-10-31