Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Archive HIGH 7.8
CVE-2023-39139

An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.

No fix yet
Fix from $1,950 2023-08-30
Gitpython MEDIUM 6.5
CVE-2023-41040

GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` …

Fix: after 3.1.34
Fix from $1,600 2023-08-30
Zip HIGH 7.8
CVE-2023-39135

An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.

No fix yet
Fix from $1,950 2023-08-30
Splunk HIGH 8.8
CVE-2023-40597

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that …

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Qlik Sense MEDIUM 6.5
CVE-2023-41266 KEVEPSS 82%

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlie…

Mitigation only
Fix from $1,600 2023-08-29
Audimexee MEDIUM 5.3
CVE-2023-39559

AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.

No fix yet
Fix from $1,600 2023-08-29
Aria Operations For Networks HIGH 7.2
CVE-2023-20890EPSS 22%

Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Ar…

Fix: 6.11.0+
Fix from $1,950 2023-08-29
Pf4j HIGH 7.5
CVE-2023-40826

An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath pa…

Fix: after 3.9.0
Fix from $1,950 2023-08-28
Pf4j HIGH 7.5
CVE-2023-40827

An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath p…

Fix: after 3.9.0
Fix from $1,950 2023-08-28
Pf4j HIGH 7.5
CVE-2023-40828

An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip meth…

Fix: after 3.9.0
Fix from $1,950 2023-08-28
Busybox HIGH 7.8
CVE-2023-39810

An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

Mitigation only
Fix from $1,950 2023-08-28
Pyramid MEDIUM 5.3
CVE-2023-40587

Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that …

Fix: 2.0.2+
Fix from $1,600 2023-08-25
Classic Web MEDIUM 6.5
CVE-2023-3406

Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated use…

Fix: 23.2 / 23.6.12695.3+
Fix from $1,600 2023-08-25
U Office Force HIGH 7.5
CVE-2023-32756

e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacke…

Mitigation only
Fix from $1,950 2023-08-25
Mail Server CRITICAL 9.8
CVE-2023-39699

IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. Thi…

No fix yet
Fix from $2,300 2023-08-25
W60b Firmware CRITICAL 9.1
CVE-2020-24113

Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive informatio…

Mitigation only
Fix from $2,300 2023-08-22
Filemage HIGH 7.5
CVE-2023-39026EPSS 11%

Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive informatio…

Fix: after 1.10.8
Fix from $1,950 2023-08-22
Webui Aria2 HIGH 7.5
CVE-2023-39141

webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

No fix yet
Fix from $1,950 2023-08-22
Edgeconnect Sd Wan Orchestrator HIGH 7.2
CVE-2023-37428

A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on …

Fix: after 9.2.5
Fix from $1,950 2023-08-22
Ak Sm 800a Firmware HIGH 8.8
CVE-2023-25914

Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The inf…

Fix: after 3.3
Fix from $1,950 2023-08-21
Typora MEDIUM 6.5
CVE-2023-2971

Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote w…

Fix: after 1.6.7
Fix from $1,600 2023-08-19
Typora HIGH 7.4
CVE-2023-2316

Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web s…

Fix: 1.6.7+
Fix from $1,950 2023-08-19
Obsidian HIGH 7.1
CVE-2023-2110

Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate the…

Fix: 1.2.8+
Fix from $1,950 2023-08-19
Jorani CRITICAL 9.8
CVE-2023-26469EPSS 83%

In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

No fix yet
Fix from $2,300 2023-08-17
Thinmanager Thinserver CRITICAL 9.1
CVE-2023-2915EPSS 84%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path tr…

Fix: after 13.0.2
Fix from $2,300 2023-08-17
Thinmanager Thinserver CRITICAL 9.8
CVE-2023-2917EPSS 72%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a pat…

Fix: after 13.0.2
Fix from $2,300 2023-08-17
Data Master HIGH 8.8
CVE-2023-3697

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …

Fix: 4.2.3.rk91+
Fix from $1,950 2023-08-17
Data Master HIGH 8.1
CVE-2023-3698

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …

Fix: 4.2.3.rk91+
Fix from $1,950 2023-08-17
Tn 5900 Firmware HIGH 8.1
CVE-2023-34216

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnera…

Fix: after 3.3
Fix from $1,950 2023-08-17
Tn 5900 Firmware HIGH 8.1
CVE-2023-34217

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnera…

Fix: after 3.3
Fix from $1,950 2023-08-17