Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Otcms HIGH 7.5
CVE-2023-3241

A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/…

Fix: after 6.62
Fix from $1,950 2023-06-14
Wp Directory Kit CRITICAL 9.8
CVE-2023-2278

The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' f…

Fix: 1.2.0+
Fix from $2,300 2023-06-13
Megarac Sp X CRITICAL 9.1
CVE-2023-34342

AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances, which ma…

Fix: 12.7 / 13.5+
Fix from $2,300 2023-06-12
Megarac Sp X MEDIUM 6.5
CVE-2023-34345

AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lead to in…

Fix: 12.7 / 13.5+
Fix from $1,600 2023-06-12
Winbizpayment HIGH 7.5
CVE-2023-30198EPSS 6%

Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

Fix: after 1.0.2
Fix from $1,950 2023-06-12
Froxlor HIGH 7.2
CVE-2023-3172

Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

Fix: 2.0.20+
Fix from $1,950 2023-06-09
Thruk HIGH 8.8
CVE-2023-34096EPSS 63%

Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, …

Fix: 3.06.2+
Fix from $1,950 2023-06-08
Gatsby MEDIUM 5.3
CVE-2023-34238

Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vul…

Fix: 4.25.7 / 5.9.1+
Fix from $1,600 2023-06-08
Roboguide Handlingpro Firmware HIGH 7.5
CVE-2023-1864

FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to a path traversal, which could allow an attacker to remotely read files on …

Fix: 9_rev.zd+
Fix from $1,950 2023-06-07
Jeecg P3 Biz Chat HIGH 7.5
CVE-2023-33510

Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

No fix yet
Fix from $1,950 2023-06-07
Adning Advertising CRITICAL 9.8
CVE-2020-36728

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows un…

Fix: 1.5.6+
Fix from $2,300 2023-06-07
Monitoring And Management CRITICAL 9.8
CVE-2023-34409

In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sani…

Fix: 2.37.1+
Fix from $2,300 2023-06-06
Cloudpanel HIGH 7.8
CVE-2023-33747

CloudPanel v2.2.2 allows attackers to execute a path traversal.

Fix: after 2.2.2
Fix from $1,950 2023-06-06
Tamale Rms MEDIUM 5.3
CVE-2023-33524

Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumerates Contact information on t…

Fix: 23.1+
Fix from $1,600 2023-06-05
Sonicjs MEDIUM 6.5
CVE-2023-33690

SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a b…

Fix: after 0.7.0
Fix from $1,600 2023-06-05
Youker Assistant HIGH 7.8
CVE-2023-3098

A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The …

Fix: 3.0.2-0kylin6k70-23+
Fix from $1,950 2023-06-05
Office Player HIGH 7.5
CVE-2023-34407

OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.

No fix yet
Fix from $1,950 2023-06-05
Firefox MEDIUM 6.5
CVE-2023-28163

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resol…

Fix: 102.9 / 111.0+
Fix from $1,600 2023-06-02
Custom Product Designer HIGH 7.5
CVE-2023-27639

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the P…

Fix: after 2.1.4
Fix from $1,950 2023-06-01
Custom Product Designer HIGH 7.5
CVE-2023-27640

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the P…

Fix: after 2.1.4
Fix from $1,950 2023-06-01
Keyboard Themes CRITICAL 9.8
CVE-2023-29736

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in i…

No fix yet
Fix from $2,300 2023-06-01
Splunk HIGH 8.1
CVE-2023-32714EPSS 43%

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path trave…

Fix: 4.0.1 / 8.1.14+
Fix from $1,950 2023-06-01
Hawtio MEDIUM 5.5
CVE-2023-33544

hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompressi…

No fix yet
Fix from $1,600 2023-06-01
Starlette HIGH 7.5
CVE-2023-29159

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files i…

Fix: 0.27.0+
Fix from $1,950 2023-06-01
Adm CRITICAL 10.0
CVE-2023-2909

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Aff…

Fix: after 4.2.1.rge2
Fix from $2,300 2023-05-31
Blog In Blog HIGH 7.2
CVE-2023-2435

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This a…

Fix: after 1.1.1
Fix from $1,950 2023-05-31
Myinventory HIGH 7.5
CVE-2023-30197

Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal informat…

Fix: 1.6.7+
Fix from $1,950 2023-05-31
Fox Datadiode Firmware CRITICAL 9.8
CVE-2022-47526

Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker c…

Mitigation only
Fix from $2,300 2023-05-31
Insight HIGH 7.1
CVE-2023-28344

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view c…

No fix yet
Fix from $1,950 2023-05-31
Xibo HIGH 8.8
CVE-2023-33177EPSS 7%

Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded…

Fix: 2.3.17 / 3.3.5+
Fix from $1,950 2023-05-30