Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Frauscher Diagnostic System 101 HIGH 7.5
CVE-2023-2880

Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal vulnerability of the web inter…

Fix: after 1.3.3
Fix from $1,950 2023-07-05
Knowage MEDIUM 6.5
CVE-2023-36819

Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/re…

Fix: 8.1.8+
Fix from $1,600 2023-07-03
Gradle MEDIUM 5.5
CVE-2023-35946

Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependen…

Fix: 7.6.2 / 8.2.0+
Fix from $1,600 2023-06-30
Gradle HIGH 8.1
CVE-2023-35947

Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…

Fix: 7.6.2 / 8.2.0+
Fix from $1,950 2023-06-30
Pleasanter MEDIUM 6.5
CVE-2023-32608

Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticate…

Fix: 1.3.39.2+
Fix from $1,600 2023-06-30
Knx Ip Router Firmware HIGH 7.5
CVE-2023-33277

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-travers…

No fix yet
Fix from $1,950 2023-06-29
Gibbon CRITICAL 9.8
CVE-2023-34598EPSS 47%

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation …

No fix yet
Fix from $2,300 2023-06-29
Traggo HIGH 7.5
CVE-2023-34843EPSS 7%

Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

No fix yet
Fix from $1,950 2023-06-29
Snow Monkey Forms CRITICAL 9.1
CVE-2023-32623

Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the s…

Fix: 5.1.2+
Fix from $2,300 2023-06-28
Aterm Wf300hp Firmware MEDIUM 5.4
CVE-2023-3331

Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG…

Mitigation only
Fix from $1,600 2023-06-28
Wcms CRITICAL 9.8
CVE-2020-19902

Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

No fix yet
Fix from $2,300 2023-06-27
Clips2 CRITICAL 9.8
CVE-2023-30945

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated…

Fix: 0.24.10 / 0.111.2+
Fix from $2,300 2023-06-26
Mobile Security CRITICAL 9.1
CVE-2023-32521EPSS 67%

A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote att…

Patch available
Fix from $2,300 2023-06-26
Mobile Security HIGH 8.1
CVE-2023-32522

A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to d…

Patch available
Fix from $1,950 2023-06-26
Apex One CRITICAL 9.8
CVE-2023-32557

A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary f…

Fix: 14.0.12105+
Fix from $2,300 2023-06-26
Multimc HIGH 7.5
CVE-2023-25306

MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal.

Fix: 0.7.0+
Fix from $1,950 2023-06-26
Mrpack Install HIGH 7.8
CVE-2023-25307

nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.

Fix: 0.16.3+
Fix from $1,950 2023-06-26
Data Catalog HIGH 7.5
CVE-2023-36301

Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.

Fix: 8.0-20230221+
Fix from $1,950 2023-06-26
Basecamp HIGH 7.5
CVE-2023-36612

Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an attacker to write arbitrary f…

Fix: 4.2.1+
Fix from $1,950 2023-06-25
Php Imap CRITICAL 9.8
CVE-2023-35169

PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsa…

Fix: 5.3.0+
Fix from $2,300 2023-06-23
Fme Server HIGH 8.1
CVE-2023-35801

A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based …

Fix: 2022.2.5+
Fix from $1,950 2023-06-23
Onlyoffice CRITICAL 9.8
CVE-2023-34939EPSS 5%

Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ash…

Fix: 12.5.2+
Fix from $2,300 2023-06-22
Nocodb HIGH 7.5
CVE-2023-35843EPSS 9%

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the serve…

Fix: after 0.106.1
Fix from $1,950 2023-06-19
Suricata HIGH 7.5
CVE-2023-35852

In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trig…

Fix: 6.0.13+
Fix from $1,950 2023-06-19
Lightdash HIGH 7.5
CVE-2023-35844EPSS 6%

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that …

Fix: 0.510.3+
Fix from $1,950 2023-06-19
Elfinder MEDIUM 6.5
CVE-2023-35840

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

Fix: 2.1.62+
Fix from $1,600 2023-06-19
Jfinal Cms HIGH 7.5
CVE-2023-34645

jfinal CMS 5.1.0 has an arbitrary file read vulnerability.

No fix yet
Fix from $1,950 2023-06-16
Cmseasy CRITICAL 9.8
CVE-2023-34880

cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vu…

No fix yet
Fix from $2,300 2023-06-15
Netskope HIGH 7.8
CVE-2023-2270

The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute comman…

Fix: 100+
Fix from $1,950 2023-06-15
Ujcms CRITICAL 9.8
CVE-2023-34865

Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.

No fix yet
Fix from $2,300 2023-06-14