Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Shop Beat Media Player MEDIUM 5.3
CVE-2022-36243

Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information …

Fix: 3.2.57+
Fix from $1,600 2023-05-30
Salesbooster HIGH 7.5
CVE-2023-30196

Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.

Fix: 1.10.5+
Fix from $1,950 2023-05-30
Device Manager Express CRITICAL 9.8
CVE-2022-24629EPSS 37%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal i…

Fix: after 7.8.20002.47752
Fix from $2,300 2023-05-29
Device Manager Express MEDIUM 5.3
CVE-2022-24632EPSS 27%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFi…

Fix: after 7.8.20002.47752
Fix from $1,600 2023-05-29
Mac1200r Firmware HIGH 7.5
CVE-2021-27825EPSS 8%

A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.

No fix yet
Fix from $1,950 2023-05-29
Warpinator HIGH 7.5
CVE-2023-29380

Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.

Fix: 1.6.0+
Fix from $1,950 2023-05-29
Autolab HIGH 7.2
CVE-2023-32676

Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the Install assessment…

Fix: 2.11.0+
Fix from $1,950 2023-05-26
Openfire HIGH 7.5
CVE-2023-32315 KEVEPSS 100%

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be…

Fix: 4.6.8 / 4.7.5+
Fix from $1,950 2023-05-26
Autolab HIGH 7.2
CVE-2023-32317

Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the MOSS cheat checker…

Fix: 2.11.0+
Fix from $1,950 2023-05-26
Blue Xp Connector MEDIUM 5.3
CVE-2023-27311

NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obta…

Fix: 3.9.25+
Fix from $1,600 2023-05-26
GitLab HIGH 7.5
CVE-2023-2825EPSS 72%

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability …

Mitigation only
Fix from $1,950 2023-05-26
Nagvis MEDIUM 6.5
CVE-2022-46945

Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.

Fix: 1.9.34+
Fix from $1,600 2023-05-26
Ess Rec HIGH 8.1
CVE-2023-28382

Directory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alter an arbitrary file on the s…

Fix: after 1.4.3
Fix from $1,950 2023-05-26
Ebx Add Ons MEDIUM 6.5
CVE-2023-26215

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application acc…

Fix: 4.5.17+
Fix from $1,600 2023-05-25
Ebx Add Ons HIGH 7.2
CVE-2023-26216

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a di…

Fix: 4.5.17+
Fix from $1,950 2023-05-25
Zlmediakit HIGH 7.5
CVE-2023-31861

ZLMediaKit 4.0 is vulnerable to Directory Traversal.

No fix yet
Fix from $1,950 2023-05-25
Mw Wp Form CRITICAL 9.8
CVE-2023-28408

Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a …

Fix: after 4.4.2
Fix from $2,300 2023-05-23
Snow Monkey Forms CRITICAL 9.8
CVE-2023-28413

Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive infor…

Fix: after 5.0.6
Fix from $2,300 2023-05-23
Mailform CRITICAL 9.8
CVE-2023-27507

MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are…

Fix: 1.1.9+
Fix from $2,300 2023-05-23
Webplus Pro CRITICAL 9.8
CVE-2020-20012

WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

No fix yet
Fix from $2,300 2023-05-23
Experience Platform HIGH 7.5
CVE-2023-27067

Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted comman…

Fix: after 10.2
Fix from $1,950 2023-05-22
Experience Platform MEDIUM 6.5
CVE-2023-27066

Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files…

Fix: after 10.2
Fix from $1,600 2023-05-22
Customexporter HIGH 7.5
CVE-2023-30199

Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.

Fix: after 1.7.20
Fix from $1,950 2023-05-19
My Cloud Os 5 CRITICAL 9.8
CVE-2022-36327

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations…

Fix: 5.26.202 / 9.4.0-191+
Fix from $2,300 2023-05-18
Identity Services Engine MEDIUM 6.7
CVE-2023-20166

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the under…

Mitigation only
Fix from $1,600 2023-05-18
Identity Services Engine MEDIUM 6.5
CVE-2023-20077

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker …

Fix: after 3.1
Fix from $1,600 2023-05-18
Identity Services Engine MEDIUM 6.5
CVE-2023-20087

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker …

Fix: after 3.1
Fix from $1,600 2023-05-18
Ip Symcon HIGH 7.5
CVE-2023-32767

The web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversa…

Fix: 6.3+
Fix from $1,950 2023-05-17
Wifi Hd Wireless Disk Drive HIGH 7.5
CVE-2023-31904

savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.

No fix yet
Fix from $1,950 2023-05-17
WordPress MEDIUM 5.4
CVE-2023-2745EPSS 80%

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated a…

Fix: 4.1.38 / 4.2.35+
Fix from $1,600 2023-05-17