Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Duo Device Health Application HIGH 7.1
CVE-2023-20229

A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with lo…

Fix: 5.2.0+
Fix from $1,950 2023-08-16
Punkbuster CRITICAL 9.8
CVE-2020-26037

Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arb…

Fix: 1.905+
Fix from $2,300 2023-08-16
Ghost MEDIUM 6.5
CVE-2023-40028EPSS 68%

Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload…

Fix: 5.59.1+
Fix from $1,600 2023-08-15
Node.js HIGH 8.8
CVE-2023-32004

A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handl…

Fix: after 20.5.0
Fix from $1,950 2023-08-15
Node.js MEDIUM 5.3
CVE-2023-32003

`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing…

Fix: after 20.5.0
Fix from $1,600 2023-08-15
Android MEDIUM 5.5
CVE-2023-21268

In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial…

Patch available
Fix from $1,600 2023-08-14
Zola HIGH 7.5
CVE-2023-40274

An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows dire…

Fix: after 0.17.2
Fix from $1,950 2023-08-14
Emui CRITICAL 9.1
CVE-2023-39402

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39400

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Emui CRITICAL 9.1
CVE-2023-39401

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri…

Mitigation only
Fix from $2,300 2023-08-13
Huemagic HIGH 7.5
CVE-2021-26504

Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted…

Patch available
Fix from $1,950 2023-08-11
Zrlog CRITICAL 9.1
CVE-2020-27514

Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbit…

No fix yet
Fix from $2,300 2023-08-11
Avalanche CRITICAL 9.8
CVE-2023-32563EPSS 89%

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

Fix: 6.4.1+
Fix from $2,300 2023-08-10
1panel HIGH 7.5
CVE-2023-39964

1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read ar…

No fix yet
Fix from $1,950 2023-08-10
Talk HIGH 7.8
CVE-2023-39957

Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allow…

Fix: 17.0.0+
Fix from $1,950 2023-08-10
Opnsense HIGH 7.2
CVE-2023-38997

A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allo…

Fix: 23.7+
Fix from $1,950 2023-08-09
Azure Arc Enabled Servers HIGH 7.0
CVE-2023-38176

Azure Arc-Enabled Servers Elevation of Privilege Vulnerability

Fix: 1.33.02399.0+
Fix from $1,950 2023-08-08
Zoom CRITICAL 9.8
CVE-2023-36534

Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network ac…

Fix: 5.14.7+
Fix from $2,300 2023-08-08
File Opener HIGH 7.8
CVE-2023-37646

An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.

Mitigation only
Fix from $1,950 2023-08-08
Foswiki HIGH 7.5
CVE-2023-33756

An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.

Fix: after 2.1.7
Fix from $1,950 2023-08-08
Foswiki HIGH 7.5
CVE-2023-24698

Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via…

Fix: after 2.1.7
Fix from $1,950 2023-08-08
Prestashop CRITICAL 9.1
CVE-2023-39525

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compromised using path traversal by…

Fix: 8.1.1+
Fix from $2,300 2023-08-07
Prestashop HIGH 8.6
CVE-2023-39528

PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can be used to read any file on th…

Fix: 8.1.1+
Fix from $1,950 2023-08-07
Textpattern HIGH 7.2
CVE-2023-36220

Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensi…

No fix yet
Fix from $1,950 2023-08-07
Flash Flood Disaster Monitoring And Warning System HIGH 7.5
CVE-2023-4172

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue af…

No fix yet
Fix from $1,950 2023-08-05
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2020-26065

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path …

Mitigation only
Fix from $1,600 2023-08-04
Knowage HIGH 8.8
CVE-2023-38702

Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/…

Fix: 8.1.8+
Fix from $1,950 2023-08-04
Cypress Image Snapshot MEDIUM 6.5
CVE-2023-38695

cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relat…

Fix: 8.0.2+
Fix from $1,600 2023-08-04
Papercut Mf CRITICAL 9.8
CVE-2023-39143EPSS 80%

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads …

Fix: 22.1.3+
Fix from $2,300 2023-08-04
Nuclei HIGH 7.5
CVE-2023-37896

Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) ru…

Fix: 2.9.9+
Fix from $1,950 2023-08-04