Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Dedecms HIGH 7.5
CVE-2023-30380

An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.

No fix yet
Fix from $1,950 2023-04-27
Pimcore MEDIUM 6.5
CVE-2023-2336

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

Fix: 10.5.21+
Fix from $1,600 2023-04-27
Ehrd Ctms HIGH 8.8
CVE-2023-24836

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can …

Mitigation only
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26243

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt …

No fix yet
Fix from $1,950 2023-04-27
Cltphp MEDIUM 6.5
CVE-2023-30265

CLTPHP <=6.0 is vulnerable to Directory Traversal.

Fix: after 6.0
Fix from $1,600 2023-04-26
Insight Agent HIGH 7.5
CVE-2023-2273

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI arg…

Fix: 3.3.0+
Fix from $1,950 2023-04-26
Git HIGH 7.5
CVE-2023-25652EPSS 52%

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by fe…

Fix: 2.30.9 / 2.31.8+
Fix from $1,950 2023-04-25
Database Performance Analyzer MEDIUM 6.5
CVE-2023-23838

Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.

Fix: 2023.2+
Fix from $1,600 2023-04-25
Contao MEDIUM 6.5
CVE-2023-29200

Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in …

Fix: 4.9.40 / 4.13.21+
Fix from $1,600 2023-04-25
Eddict Player CRITICAL 9.8
CVE-2023-27105

A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music …

No fix yet
Fix from $2,300 2023-04-25
Jellyfin HIGH 8.1
CVE-2023-30626

Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid…

Fix: 10.8.10+
Fix from $1,950 2023-04-24
Usg Flex 100 Firmware HIGH 7.2
CVE-2023-22914

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series fi…

Fix: after 5.35
Fix from $1,950 2023-04-24
Ktor HIGH 7.5
CVE-2022-48476

In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible

Fix: 2.3.0+
Fix from $1,950 2023-04-24
Repetier Server HIGH 7.5
CVE-2023-31059EPSS 6%

Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.

Fix: after 1.4.10
Fix from $1,950 2023-04-24
Bmc HIGH 7.8
CVE-2023-25508

NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download …

Fix: 3.39.30+
Fix from $1,950 2023-04-22
Mindsdb HIGH 7.5
CVE-2023-30620

mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction is being performed using `tar…

Fix: after 23.1.5.0
Fix from $1,950 2023-04-21
Flowmon Packet Investigator HIGH 7.5
CVE-2023-26101

In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vuln…

Fix: 12.1.0+
Fix from $1,950 2023-04-21
Pretalx MEDIUM 6.5
CVE-2023-28459EPSS 7%

pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigge…

Fix: after 2.3.1
Fix from $1,600 2023-04-20
Android HIGH 7.8
CVE-2023-21093

In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traver…

Patch available
Fix from $1,950 2023-04-19
Spreadsheet Reader HIGH 7.5
CVE-2023-29887

A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File paramet…

No fix yet
Fix from $1,950 2023-04-18
Roxy Wi MEDIUM 6.5
CVE-2023-29004

hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerability was found in the current…

Fix: after 6.3.9.0
Fix from $1,600 2023-04-17
Energy Axc Pu HIGH 8.8
CVE-2023-1109

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughou…

Fix: after 04.15.00.00
Fix from $1,950 2023-04-17
Activity HIGH 7.5
CVE-2022-34126

The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.

Fix: 3.1.1+
Fix from $1,950 2023-04-16
Manageentities HIGH 7.5
CVE-2022-34127EPSS 7%

The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.

Fix: 4.0.2+
Fix from $1,950 2023-04-16
Ofbiz HIGH 7.5
CVE-2022-47501EPSS 10%

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. Thi…

Fix: 18.12.07+
Fix from $1,950 2023-04-14
Oxygen Content Fusion MEDIUM 5.3
CVE-2023-26559

A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015…

Fix: 5.0.3 / 23.1.1.4+
Fix from $1,600 2023-04-14
Fast Typing Keyboard CRITICAL 9.8
CVE-2022-47027

Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary travers…

No fix yet
Fix from $2,300 2023-04-14
Change Color Of Keypad CRITICAL 9.8
CVE-2023-27648

Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via t…

No fix yet
Fix from $2,300 2023-04-14
Atropim HIGH 7.5
CVE-2023-26969

Atropim 1.5.26 is vulnerable to Directory Traversal.

No fix yet
Fix from $1,950 2023-04-14
Bloofoxcms CRITICAL 9.1
CVE-2023-27812

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

Mitigation only
Fix from $2,300 2023-04-13