Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Office Suite HIGH 7.5
CVE-2023-37601

Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.

No fix yet
Fix from $1,950 2023-07-20
Gg HIGH 7.5
CVE-2023-31461

Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled…

No fix yet
Fix from $1,950 2023-07-20
Thinmanager MEDIUM 6.5
CVE-2023-2913

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This featur…

Fix: after 13.0.2
Fix from $1,600 2023-07-18
Openrefine HIGH 7.8
CVE-2023-37476

OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrar…

Fix: after 3.7.3
Fix from $1,950 2023-07-17
Metersphere CRITICAL 9.8
CVE-2023-37461

Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../…

Fix: 2.10.3+
Fix from $2,300 2023-07-17
Emqx MEDIUM 6.5
CVE-2023-37781

An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.

No fix yet
Fix from $1,600 2023-07-17
Rswag HIGH 7.5
CVE-2023-38337

rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that i…

Fix: 2.10.1+
Fix from $1,950 2023-07-14
Copyparty HIGH 7.5
CVE-2023-37474EPSS 45%

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path…

Fix: 1.8.2+
Fix from $1,950 2023-07-14
Bullwark Momentum Series HIGH 7.5
CVE-2023-35069

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal. This issue affects B…

Mitigation only
Fix from $1,950 2023-07-13
Analytics MEDIUM 6.5
CVE-2023-34135

Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file s…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Analytics HIGH 8.8
CVE-2023-34129EPSS 41%

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated r…

Fix: 9.3.2+
Fix from $1,950 2023-07-13
Analytics MEDIUM 6.5
CVE-2023-34125EPSS 25%

Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root p…

Fix: 9.3.2+
Fix from $1,600 2023-07-13
Ej2 Aspcore File Provider CRITICAL 9.8
CVE-2023-26564

The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated…

No fix yet
Fix from $2,300 2023-07-12
Nodejs File System Provider CRITICAL 9.8
CVE-2023-26563

The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can…

No fix yet
Fix from $2,300 2023-07-12
Mathworks Polyspace MEDIUM 6.5
CVE-2023-37960

Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jen…

Fix: after 1.0.5
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-22887

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Fortianalyzer MEDIUM 6.5
CVE-2023-25606

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management…

Fix: 6.4.12 / 7.2.2+
Fix from $1,600 2023-07-11
Fortiextender Firmware HIGH 7.5
CVE-2022-23447

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0…

Fix: 3.2.4 / 3.3.3+
Fix from $1,950 2023-07-11
Netweaver Bi Content HIGH 8.1
CVE-2023-33989

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal…

Mitigation only
Fix from $1,950 2023-07-11
Fedora MEDIUM 5.5
CVE-2023-1183EPSS 65%

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the content…

Fix: 7.4.6+
Fix from $1,600 2023-07-10
Smartbpm.net HIGH 7.5
CVE-2023-37288

SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this v…

Mitigation only
Fix from $1,950 2023-07-10
Mastodon CRITICAL 9.9
CVE-2023-36460EPSS 40%

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, …

Fix: 3.5.9 / 4.0.5+
Fix from $2,300 2023-07-06
Ur32l Firmware MEDIUM 6.5
CVE-2023-23547

A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network re…

No fix yet
Fix from $1,600 2023-07-06
Milesightvpn HIGH 7.5
CVE-2023-23907

A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead…

No fix yet
Fix from $1,950 2023-07-06
Duxcms HIGH 8.1
CVE-2020-21862

Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.

No fix yet
Fix from $1,950 2023-07-06
Calendar MEDIUM 5.5
CVE-2023-30678

Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.

Fix: 12.4.07.15+
Fix from $1,600 2023-07-06
Aspen HIGH 7.8
CVE-2023-24256

An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.

Fix: 3.3.0+
Fix from $1,950 2023-07-06
Fides HIGH 7.5
CVE-2023-36827

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…

Fix: 2.15.1+
Fix from $1,950 2023-07-05
Uptime Kuma HIGH 8.1
CVE-2023-36822

Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to…

Fix: 1.22.1+
Fix from $1,950 2023-07-05
Arubaos HIGH 8.1
CVE-2023-35975

An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in …

Fix: 8.6.0.21 / 8.10.0.7+
Fix from $1,950 2023-07-05