Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Edgeconnect Enterprise MEDIUM 6.5
CVE-2023-30509

Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of th…

Fix: after 9.2.3.0
Fix from $1,600 2023-05-16
Edgeconnect Enterprise MEDIUM 6.5
CVE-2023-30507

Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of th…

Fix: after 9.2.3.0
Fix from $1,600 2023-05-16
Edgeconnect Enterprise MEDIUM 6.5
CVE-2023-30508

Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of th…

Fix: after 9.2.3.0
Fix from $1,600 2023-05-16
Greenplum Database CRITICAL 9.1
CVE-2023-31131

Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods…

Fix: 6.22.3+
Fix from $2,300 2023-05-15
Pymdown Extensions HIGH 7.5
CVE-2023-32309

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when us…

Fix: 10.0+
Fix from $1,950 2023-05-15
Enterprise Va Max HIGH 8.1
CVE-2020-13377

The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to condu…

Fix: after 8.3.8
Fix from $1,950 2023-05-12
Pdfocus MEDIUM 6.5
CVE-2023-23169

Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.

No fix yet
Fix from $1,600 2023-05-12
Gl S20 Firmware HIGH 7.5
CVE-2023-31477

A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directo…

Fix: 3.216+
Fix from $1,950 2023-05-11
Spring Boot Actuator Logview MEDIUM 5.3
CVE-2023-29986

spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.

Mitigation only
Fix from $1,600 2023-05-11
Mlflow HIGH 7.5
CVE-2023-30172

A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on t…

Fix: 2.0.1+
Fix from $1,950 2023-05-11
N8n MEDIUM 6.5
CVE-2023-27562

The n8n package 0.218.0 for Node.js allows Directory Traversal.

No fix yet
Fix from $1,600 2023-05-10
Nuc Pro Software Suite HIGH 7.8
CVE-2022-34855

Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of pri…

Fix: 2.0.0.3+
Fix from $1,950 2023-05-10
M.static MEDIUM 5.3
CVE-2023-26126

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the req…

Fix: after 2.2.0
Fix from $1,600 2023-05-10
Avalanche HIGH 7.5
CVE-2023-28127EPSS 59%

A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.

Fix: after 6.3.4.153
Fix from $1,950 2023-05-09
Catalyst Sd Wan Manager MEDIUM 6.0
CVE-2023-20098

A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerabil…

Fix: 20.9.1+
Fix from $1,600 2023-05-09
6gk1411 1ac00 Firmware HIGH 7.6
CVE-2023-29104

A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2…

Patch available
Fix from $1,950 2023-05-09
Innokb HIGH 7.5
CVE-2023-31181

WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal

Mitigation only
Fix from $1,950 2023-05-08
Agilepoint Nx HIGH 7.5
CVE-2023-31179

AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the server, by an unspecified requ…

Mitigation only
Fix from $1,950 2023-05-08
Pimcore HIGH 7.5
CVE-2023-30855

Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact …

Fix: 10.5.18+
Fix from $1,950 2023-05-08
Ghost HIGH 7.5
CVE-2023-32235EPSS 39%

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traver…

Fix: 5.42.1+
Fix from $1,950 2023-05-05
Digital Reciptie HIGH 7.5
CVE-2023-25289EPSS 8%

Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, all…

No fix yet
Fix from $1,950 2023-05-04
Cltphp CRITICAL 9.8
CVE-2023-30268

CLTPHP <=6.0 is vulnerable to Improper Input Validation.

Fix: after 6.0
Fix from $2,300 2023-05-04
Powersoft HIGH 7.5
CVE-2017-20184

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows …

Fix: after 2.1.1.1
Fix from $1,950 2023-05-04
Imo CRITICAL 9.8
CVE-2022-47757

In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the appli…

Mitigation only
Fix from $2,300 2023-05-04
Fortiadc HIGH 7.1
CVE-2023-27993

A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories f…

Fix: 7.1.2+
Fix from $1,950 2023-05-03
Cloud HIGH 8.8
CVE-2022-47875EPSS 10%

A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

No fix yet
Fix from $1,950 2023-05-02
3cx HIGH 7.5
CVE-2022-48483

3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download dir…

Fix: 18.0.3.461+
Fix from $1,950 2023-05-02
3cx HIGH 7.5
CVE-2022-48482

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/downlo…

Fix: 18.0.2.315+
Fix from $1,950 2023-05-02
Ip Blacklist Cloud CRITICAL 9.8
CVE-2015-10105

A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This affects the function valid_js…

Fix: after 3.42
Fix from $2,300 2023-05-01
Cbang HIGH 7.5
CVE-2023-31483

tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write…

Fix: 8.1.17+
Fix from $1,950 2023-04-28