Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Bigbluebutton MEDIUM 5.3
CVE-2023-42804

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an atta…

Fix: after 2.5.18
Fix from $1,600 2023-10-30
Basercms MEDIUM 6.5
CVE-2023-43648

baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data managem…

Fix: 4.8.0+
Fix from $1,600 2023-10-30
Peppermint HIGH 7.5
CVE-2023-46863

Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST reque…

Fix: 0.2.4+
Fix from $1,950 2023-10-30
Peppermint MEDIUM 5.3
CVE-2023-46864

Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST req…

Fix: after 0.2.4
Fix from $1,600 2023-10-30
Secure Files CRITICAL 9.8
CVE-2005-10002

A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function…

Fix: 1.2+
Fix from $2,300 2023-10-29
Write Back Manager HIGH 7.5
CVE-2023-27170

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

No fix yet
Fix from $1,950 2023-10-26
Tvip 10000 Firmware HIGH 8.8
CVE-2018-16739

An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus e…

No fix yet
Fix from $1,950 2023-10-26
Ilias MEDIUM 6.5
CVE-2023-45867

ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker …

No fix yet
Fix from $1,600 2023-10-26
Ilias HIGH 8.1
CVE-2023-45868

The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal a…

No fix yet
Fix from $1,950 2023-10-26
Orbital Simulator HIGH 7.5
CVE-2023-30967

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbit…

Fix: 0.692.0+
Fix from $1,950 2023-10-26
Exportproducts HIGH 7.5
CVE-2023-46346

In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest ca…

Fix: 5.0.0+
Fix from $1,950 2023-10-25
Parse Server HIGH 7.5
CVE-2023-46119

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file wi…

Fix: 5.5.6 / 6.3.1+
Fix from $1,950 2023-10-25
Eisbaer Scada HIGH 7.5
CVE-2023-42488

EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Fix: after 3.0.6433.1964
Fix from $1,950 2023-10-25
Xwiki HIGH 8.8
CVE-2023-37913

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prio…

Fix: 14.10.8 / 15.3+
Fix from $1,950 2023-10-25
Idweb HIGH 8.8
CVE-2023-26578

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root su…

Mitigation only
Fix from $1,950 2023-10-25
Agevolt HIGH 8.8
CVE-2022-38484

An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prio…

Fix: 0.1+
Fix from $1,950 2023-10-25
Agevolt MEDIUM 6.5
CVE-2022-38485

A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated at…

Fix: 0.1+
Fix from $1,600 2023-10-25
Io HIGH 7.1
CVE-2023-46122

sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would h…

Fix: 1.9.7+
Fix from $1,950 2023-10-23
Client Connector HIGH 7.8
CVE-2021-26736

Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low …

Fix: 3.6+
Fix from $1,950 2023-10-23
Codered Extensions MEDIUM 6.5
CVE-2021-46897

views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when …

Fix: 0.22.3+
Fix from $1,600 2023-10-22
Fortianalyzer MEDIUM 6.5
CVE-2023-44256

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and Forti…

Fix: after 7.2.3
Fix from $1,600 2023-10-20
Icegram Express HIGH 7.2
CVE-2023-5414

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function.…

Fix: after 5.6.23
Fix from $1,950 2023-10-20
Migration\, Backup\, Staging MEDIUM 6.5
CVE-2023-4274

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This all…

Fix: 0.9.90+
Fix from $1,600 2023-10-20
Hub HIGH 7.5
CVE-2023-45823

Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a secu…

Fix: 1.16.0+
Fix from $1,950 2023-10-19
Yamcs HIGH 7.5
CVE-2023-45277

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escap…

Patch available
Fix from $1,950 2023-10-19
Yamcs CRITICAL 9.1
CVE-2023-45278

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP …

Patch available
Fix from $2,300 2023-10-19
Access Rights Manager MEDIUM 6.8
CVE-2023-35185

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges.

Fix: after 2023.2.0.73
Fix from $1,600 2023-10-19
Access Rights Manager CRITICAL 9.8
CVE-2023-35187

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated…

Fix: after 2023.2.0.73
Fix from $2,300 2023-10-19
Papercut Mf MEDIUM 6.5
CVE-2023-31046

A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially a…

Fix: 22.1.1+
Fix from $1,600 2023-10-19
Wpbot HIGH 8.1
CVE-2023-5212

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This m…

Fix: 4.9.1+
Fix from $1,950 2023-10-19