Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Static Server HIGH 7.5
CVE-2023-26152

All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function …

Fix: after 3.0.0
Fix from $1,950 2023-10-03
Acera 1310 Firmware MEDIUM 5.7
CVE-2023-43627

Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent au…

Fix: after 01.26
Fix from $1,600 2023-10-03
Cl4nx J Plus Firmware MEDIUM 6.5
CVE-2023-5327

A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic. Affected by this issue is some unknown functionality…

Mitigation only
Fix from $1,600 2023-10-01
Enterprise Wi Fi HIGH 8.8
CVE-2022-35908

Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.

Fix: 6.4.2+
Fix from $1,950 2023-09-29
Jndiexploit MEDIUM 5.7
CVE-2023-5257

A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFil…

No fix yet
Fix from $1,600 2023-09-29
Shokoserver HIGH 8.6
CVE-2023-43662EPSS 8%

ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without au…

Fix: after 4.2.2
Fix from $1,950 2023-09-28
License Metric Tool HIGH 7.5
CVE-2023-43044

IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL reque…

Fix: 9.2.33+
Fix from $1,950 2023-09-28
Seacms CRITICAL 9.8
CVE-2023-44169

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

No fix yet
Fix from $2,300 2023-09-27
Seacms CRITICAL 9.8
CVE-2023-44170

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

No fix yet
Fix from $2,300 2023-09-27
Seacms CRITICAL 9.8
CVE-2023-44171

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

No fix yet
Fix from $2,300 2023-09-27
Seacms CRITICAL 9.8
CVE-2023-44172

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

No fix yet
Fix from $2,300 2023-09-27
Shihonkanri Plus HIGH 7.8
CVE-2023-43825

Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arbitrary code by having a legit…

Fix: after 9.0.3
Fix from $1,950 2023-09-27
Jumpserver HIGH 8.8
CVE-2023-42819

JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Temp…

Fix: 3.6.5+
Fix from $1,950 2023-09-27
Seacms CRITICAL 9.8
CVE-2023-43216

SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

No fix yet
Fix from $2,300 2023-09-27
Glpi CRITICAL 9.1
CVE-2023-42462

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $2,300 2023-09-27
Soundminer HIGH 7.5
CVE-2023-42487

Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Fix: 2.01+
Fix from $1,950 2023-09-27
Ws Ftp Server CRITICAL 9.6
CVE-2023-42657EPSS 17%

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker could leverage this vulnerabilit…

Fix: 8.7.4 / 8.8.2+
Fix from $2,300 2023-09-27
Glpi MEDIUM 5.4
CVE-2023-41888

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,600 2023-09-27
Opencart HIGH 8.8
CVE-2023-2315

Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out ar…

Fix: after 4.0.2.2
Fix from $1,950 2023-09-27
Integration Camel K HIGH 7.5
CVE-2022-4244

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…

Fix: 1.10.1 / 3.0.24+
Fix from $1,950 2023-09-25
Dreamer Cms HIGH 8.8
CVE-2023-43382

Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the themePath in the uploade…

Mitigation only
Fix from $1,950 2023-09-25
Gladys Assistant MEDIUM 6.5
CVE-2023-43256

A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a …

Fix: after 4.26.1
Fix from $1,600 2023-09-25
Emui HIGH 7.5
CVE-2023-41302

Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perf…

No fix yet
Fix from $1,950 2023-09-25
Harmonyos CRITICAL 9.1
CVE-2023-39407

The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

No fix yet
Fix from $2,300 2023-09-25
Gr 1100 P Firmware MEDIUM 5.3
CVE-2023-5142

A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER…

Fix: after 20230908
Fix from $1,600 2023-09-24
Vxworks HIGH 8.8
CVE-2023-38346

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files …

Patch available
Fix from $1,950 2023-09-22
Mee Admin HIGH 7.5
CVE-2023-42280

mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not verify the incoming data, resu…

No fix yet
Fix from $1,950 2023-09-21
Sudo HIGH 8.1
CVE-2023-42456

Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requir…

Fix: 0.2.1+
Fix from $1,950 2023-09-21
Remote Application Platform CRITICAL 9.8
CVE-2023-4760

In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. …

Fix: after 3.25.0
Fix from $2,300 2023-09-21
Frauscher Diagnostic System 101 HIGH 7.5
CVE-2023-4152

Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal vulnerability of the web inte…

Fix: after 1.4.24
Fix from $1,950 2023-09-21