Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Yii CRITICAL 9.8
CVE-2015-5467

web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.

Fix: 2.0.5+
Fix from $2,300 2023-09-21
Skyworth Os MEDIUM 6.8
CVE-2023-40930

An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.

No fix yet
Fix from $1,600 2023-09-20
M4 Pdf MEDIUM 6.5
CVE-2022-45447

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not p…

Fix: after 3.2.3
Fix from $1,600 2023-09-20
Croc MEDIUM 5.5
CVE-2023-43616

An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.

Fix: after 9.6.5
Fix from $1,600 2023-09-20
Jfinalcms MEDIUM 5.3
CVE-2023-41599EPSS 11%

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

No fix yet
Fix from $1,600 2023-09-19
Nats Server CRITICAL 9.8
CVE-2022-28357

NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

Fix: after 2.7.4
Fix from $2,300 2023-09-19
I Doit MEDIUM 6.5
CVE-2023-37739

i-doit Pro v25 and below was discovered to be vulnerable to path traversal.

Fix: after 25
Fix from $1,600 2023-09-14
Routinator MEDIUM 6.5
CVE-2023-39916

NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability…

Fix: 0.12.2+
Fix from $1,600 2023-09-13
Cecil HIGH 7.5
CVE-2023-4914

Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.

Fix: 7.47.1+
Fix from $1,950 2023-09-12
Node.js HIGH 7.5
CVE-2023-32558

The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnerability affects all users usin…

Fix: 20.5.1+
Fix from $1,950 2023-09-12
Android HIGH 7.8
CVE-2023-35670

In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path travers…

Patch available
Fix from $1,950 2023-09-11
Maglink Lx Web Console Configuration HIGH 7.5
CVE-2023-38256

Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 vulnerable to a path trav…

Mitigation only
Fix from $1,950 2023-09-11
Security Directory Server CRITICAL 9.1
CVE-2022-33164

IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted U…

Patch available
Fix from $2,300 2023-09-08
Jeecg Boot HIGH 7.5
CVE-2023-41578

Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.

Fix: after 3.5.3
Fix from $1,950 2023-09-08
Terraform HIGH 7.8
CVE-2023-4782

Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. …

Fix: 1.5.7+
Fix from $1,950 2023-09-08
Solarview Compact Firmware HIGH 7.5
CVE-2023-40924

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

Fix: 6.0+
Fix from $1,950 2023-09-08
Hexo HIGH 7.5
CVE-2023-39584EPSS 32%

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

Fix: after 6.3.0
Fix from $1,950 2023-09-08
Acrobat HIGH 7.8
CVE-2021-28644

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Path travers…

Fix: 17.011.30199 / 20.004.30006+
Fix from $1,950 2023-09-06
Acrobat HIGH 7.8
CVE-2021-35980

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Path travers…

Fix: 17.011.30199 / 20.004.30006+
Fix from $1,950 2023-09-06
Phpfusion MEDIUM 5.5
CVE-2023-4480

Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request th…

Fix: after 9.10.30
Fix from $1,600 2023-09-05
Shirasagi HIGH 8.8
CVE-2023-39448

Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, …

Fix: 1.18.0+
Fix from $1,950 2023-09-05
Ufida Nc HIGH 7.5
CVE-2023-4748

A vulnerability, which was classified as critical, has been found in Yongyou UFIDA-NC up to 20230807. This issue affects some unknown processing of t…

No fix yet
Fix from $1,950 2023-09-05
Hyper Bump It MEDIUM 5.5
CVE-2023-41057

hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern from the configuration file.…

Fix: 0.5.1+
Fix from $1,600 2023-09-04
Lg Led Assistant CRITICAL 9.8
CVE-2023-4614

This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…

Mitigation only
Fix from $2,300 2023-09-04
Lg Led Assistant HIGH 7.5
CVE-2023-4615

This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…

Mitigation only
Fix from $1,950 2023-09-04
Lg Led Assistant HIGH 7.5
CVE-2023-4616

This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…

Mitigation only
Fix from $1,950 2023-09-04
Lg Led Assistant CRITICAL 9.8
CVE-2023-4613

This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…

Mitigation only
Fix from $2,300 2023-09-04
Cloud Manager MEDIUM 6.5
CVE-2023-41747

Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Cloud Manager (Windows) before b…

Fix: 6.2.23089.203+
Fix from $1,600 2023-08-31
Sel 5036 Acselerator Bay Screen Builder HIGH 8.1
CVE-2023-31167

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering Laboratories SEL-5036 acSELera…

Fix: 1.0.49152.778+
Fix from $1,950 2023-08-31
Zipfoundation HIGH 7.8
CVE-2023-39138

An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

No fix yet
Fix from $1,950 2023-08-30