Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Wpbot HIGH 8.1
CVE-2023-5241

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload…

Fix: 4.9.1+
Fix from $1,950 2023-10-19
Create Agent HIGH 7.1
CVE-2023-43801

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way …

Fix: 1.3.3+
Fix from $1,950 2023-10-18
Create Agent HIGH 7.8
CVE-2023-43802

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with th…

Fix: 1.3.3+
Fix from $1,950 2023-10-18
Create Agent HIGH 7.1
CVE-2023-43803

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way …

Fix: 1.3.3+
Fix from $1,950 2023-10-18
Sonice Etiquetage HIGH 7.5
CVE-2023-45383

In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal informat…

Fix: after 2.5.9
Fix from $1,950 2023-10-18
Node.js HIGH 7.5
CVE-2023-39331

A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises becau…

Fix: 20.8.1+
Fix from $1,950 2023-10-18
Node.js CRITICAL 9.8
CVE-2023-39332

Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the…

Fix: 20.8.0+
Fix from $2,300 2023-10-18
Mailhunter Ultimate MEDIUM 6.5
CVE-2023-34208

Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arb…

Fix: after 2023
Fix from $1,600 2023-10-17
Exos HIGH 7.5
CVE-2023-43121

A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and befor…

Fix: 22.7 / 31.7.2+
Fix from $1,950 2023-10-16
Titan Mfp Server HIGH 7.2
CVE-2023-45686

Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenti…

Fix: 2.0.18+
Fix from $1,950 2023-10-16
Titan Mft Server MEDIUM 6.5
CVE-2023-45689

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacke…

Fix: 2.0.18+
Fix from $1,600 2023-10-16
Titan Mft Server CRITICAL 9.1
CVE-2023-45685

Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows …

Fix: 2.0.18+
Fix from $2,300 2023-10-16
Axis Os HIGH 8.1
CVE-2023-21415

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that all…

Fix: 6.50.5.2 / 6.50.5.14+
Fix from $1,950 2023-10-16
Pleroma MEDIUM 5.3
CVE-2023-5588

A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emoji.Pack of the file lib/plero…

Patch available
Fix from $1,600 2023-10-15
Counter Strike HIGH 7.5
CVE-2023-38312

A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary file…

Mitigation only
Fix from $1,950 2023-10-15
Security Directory Integrator HIGH 7.5
CVE-2022-33165

IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted U…

Patch available
Fix from $1,950 2023-10-14
Qdpm HIGH 7.5
CVE-2023-45855

qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

No fix yet
Fix from $1,950 2023-10-14
Qts HIGH 7.5
CVE-2023-32974

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users …

Fix: 5.1.0.2444+
Fix from $1,950 2023-10-13
Fortisandbox HIGH 7.5
CVE-2023-41682

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 thr…

Fix: after 4.2.5
Fix from $1,950 2023-10-13
Espeak Ng HIGH 7.5
CVE-2023-4990

Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files.

Fix: 1.52.0 / 4.6.0.30210+
Fix from $1,950 2023-10-11
Big Ip Access Policy Manager CRITICAL 9.9
CVE-2023-41373

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BI…

Fix: 14.1.5.6 / 15.1.10.2+
Fix from $2,300 2023-10-10
Cp 8050 Firmware HIGH 8.8
CVE-2023-42796

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11). Th…

Fix: 05.11+
Fix from $1,950 2023-10-10
Unify Openscape Common Management HIGH 8.8
CVE-2023-45352

Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the…

Mitigation only
Fix from $1,950 2023-10-09
Plain Craft Launcher 2 HIGH 7.8
CVE-2023-36123

Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain…

No fix yet
Fix from $1,950 2023-10-07
Music Station MEDIUM 6.5
CVE-2023-23365

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the…

Fix: 5.3.22+
Fix from $1,600 2023-10-06
Music Station MEDIUM 6.5
CVE-2023-23366

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the…

Fix: 5.3.22+
Fix from $1,600 2023-10-06
Smartfabric Storage Software MEDIUM 6.5
CVE-2023-43070

Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A remote authenticated attacker c…

Fix: 1.4.1+
Fix from $1,600 2023-10-05
Spacelogic C Bus Toolkit CRITICAL 9.8
CVE-2023-5399EPSS 39%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on …

Fix: 1.16.4+
Fix from $2,300 2023-10-04
Conacwin HIGH 7.5
CVE-2023-3512

Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an…

Fix: after 3.8.2.2
Fix from $1,950 2023-10-04
Aqua Drive HIGH 8.8
CVE-2023-3701

Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non priv…

Mitigation only
Fix from $1,950 2023-10-04