Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Pimcore HIGH 8.8
CVE-2023-38708

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist…

Fix: 10.6.7+
Fix from $1,950 2023-08-04
Biotime HIGH 7.5
CVE-2023-38950 KEVEPSS 85%

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a cr…

Fix: 9.0.1+
Fix from $1,950 2023-08-03
Biotime CRITICAL 9.8
CVE-2023-38951

ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server vi…

Mitigation only
Fix from $2,300 2023-08-03
Telwin Scada Webinterface HIGH 7.5
CVE-2023-0956

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special …

Fix: 6.2 / 7.2+
Fix from $1,950 2023-08-03
Endpoint Manager Mobile HIGH 7.2
CVE-2023-35081 KEVEPSS 64%

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated admini…

Fix: 11.8.1.2 / 11.9.1.2+
Fix from $1,950 2023-08-03
Biostar 2 HIGH 7.5
CVE-2023-33365

A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the ser…

Fix: 2.9.1+
Fix from $1,950 2023-08-03
Wrangler MEDIUM 5.7
CVE-2023-3348

The Wrangler command line tool  (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local deve…

Fix: 3.1.1+
Fix from $1,600 2023-08-03
Remote Service Manager MEDIUM 6.5
CVE-2022-26838

Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-…

Mitigation only
Fix from $1,600 2023-08-03
Bioaccess Ivs HIGH 7.5
CVE-2023-38956

A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payloa…

Mitigation only
Fix from $1,950 2023-08-03
Control Id Idsecure CRITICAL 9.1
CVE-2023-33369

A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem,…

Fix: after 4.7.26.0
Fix from $2,300 2023-08-03
Scadawebserver MEDIUM 6.5
CVE-2023-3329

SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite fi…

Fix: after 2.08
Fix from $1,600 2023-08-02
Open Xchange Appsuite Office MEDIUM 5.5
CVE-2023-26441

Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi…

Fix: 8.11+
Fix from $1,600 2023-08-02
GitLab MEDIUM 6.5
CVE-2023-3385

An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all ve…

Fix: 16.0.8 / 16.1.3+
Fix from $1,600 2023-08-02
Fabric Operating System HIGH 7.8
CVE-2023-31427

Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names in…

Fix: 9.1.1c+
Fix from $1,950 2023-08-01
Spectrum Spatial Analyst MEDIUM 5.3
CVE-2022-42182

Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal.

Patch available
Fix from $1,600 2023-07-31
Security Verify Governance MEDIUM 6.5
CVE-2023-35016

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a s…

Mitigation only
Fix from $1,600 2023-07-31
Aeonix HIGH 7.5
CVE-2023-37218

Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Mitigation only
Fix from $1,950 2023-07-30
Jreport HIGH 7.5
CVE-2020-22623

Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information.

Mitigation only
Fix from $1,950 2023-07-27
Network Configuration Monitor HIGH 7.2
CVE-2023-23842

The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administr…

Fix: 2023.3.0+
Fix from $1,950 2023-07-26
Rtx Trap HIGH 7.5
CVE-2022-31457

RTX TRAP v1.0 allows attackers to perform a directory traversal via a crafted request sent to the endpoint /data/.

Mitigation only
Fix from $1,950 2023-07-25
Report Server MEDIUM 6.5
CVE-2022-46900

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Repor…

Fix: after 5.8.0.135
Fix from $1,600 2023-07-25
Report Server HIGH 7.5
CVE-2022-46902

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report…

Fix: after 5.8.0.135
Fix from $1,950 2023-07-25
Plexus Archiver CRITICAL 9.8
CVE-2023-37460

Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API…

Fix: 4.8.0+
Fix from $2,300 2023-07-25
Report Server CRITICAL 9.8
CVE-2022-46898

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vo…

Fix: after 5.8.0.135
Fix from $2,300 2023-07-25
Amazon MEDIUM 5.3
CVE-2023-33777

An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.

Fix: 5.2.24+
Fix from $1,600 2023-07-25
Nodebb CRITICAL 9.8
CVE-2023-26045

NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…

Fix: 2.8.7+
Fix from $2,300 2023-07-24
Shiro CRITICAL 9.8
CVE-2023-34478

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…

Fix: 1.12.0+
Fix from $2,300 2023-07-24
Fedora MEDIUM 5.5
CVE-2023-38633

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local …

Fix: 2.46.6 / 2.48.11+
Fix from $1,600 2023-07-22
Jupiter X Core HIGH 7.5
CVE-2023-3813

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for…

Fix: after 2.5.0
Fix from $1,950 2023-07-21
Ultimateimagetool HIGH 7.5
CVE-2023-30200

In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop,…

Fix: 2.1.03+
Fix from $1,950 2023-07-20