Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Forticlient HIGH 7.8
CVE-2022-42470

A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an at…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Tia Portal HIGH 7.3
CVE-2023-26293

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TI…

Patch available
Fix from $1,950 2023-04-11
Netweaver MEDIUM 6.5
CVE-2023-29186EPSS 23%

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrit…

Mitigation only
Fix from $1,600 2023-04-11
Hummingbird CRITICAL 9.8
CVE-2023-1478

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path t…

Fix: 3.4.2+
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-27603

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Online Computer And Laptop Store HIGH 8.8
CVE-2023-1956

A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown…

No fix yet
Fix from $1,950 2023-04-08
Bibliocraft CRITICAL 9.8
CVE-2023-29478

BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesys…

Fix: 2.4.6+
Fix from $2,300 2023-04-07
Siteproxy HIGH 7.5
CVE-2023-26820

siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.

No fix yet
Fix from $1,950 2023-04-07
Pfsense HIGH 7.5
CVE-2020-19678

Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive info…

Patch available
Fix from $1,950 2023-04-06
Prime Infrastructure MEDIUM 6.5
CVE-2023-20129

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) co…

Fix: 3.10.2 / 5.0.2.5+
Fix from $1,600 2023-04-05
Wide CRITICAL 9.8
CVE-2020-19279

Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.

Mitigation only
Fix from $2,300 2023-04-04
Atlauncher HIGH 7.1
CVE-2023-25303

ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the instal…

Fix: 3.4.27.0+
Fix from $1,950 2023-04-04
Polymc HIGH 7.1
CVE-2023-25305

PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the inst…

Fix: 5.0+
Fix from $1,950 2023-04-04
Vantara Pentaho Business Analytics Server MEDIUM 6.5
CVE-2022-43771EPSS 24%

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes …

Fix: 9.3.0.1+
Fix from $1,600 2023-04-03
Curl HIGH 8.8
CVE-2023-27534

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix …

Fix: after 7.88.1
Fix from $1,950 2023-03-30
Mindsdb HIGH 8.8
CVE-2022-23522

MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archive()` from a remotely retrieve…

Fix: 22.11.4.3+
Fix from $1,950 2023-03-30
Nextcloud Server HIGH 8.8
CVE-2023-28833

Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to …

Fix: 23.0.14 / 24.0.10+
Fix from $1,950 2023-03-30
Acymailing HIGH 7.5
CVE-2023-28732

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access…

Fix: 8.3.0+
Fix from $1,950 2023-03-30
Avalanche CRITICAL 9.8
CVE-2022-36981EPSS 83%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche HIGH 7.5
CVE-2022-36982EPSS 74%

This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication i…

Fix: 6.3.4+
Fix from $1,950 2023-03-29
Completeftp Server CRITICAL 9.1
CVE-2022-2560EPSS 78%

This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authenticat…

Fix: 22.1.1+
Fix from $2,300 2023-03-29
Muyucms HIGH 8.1
CVE-2023-27700

MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html.

No fix yet
Fix from $1,950 2023-03-28
Emui MEDIUM 5.3
CVE-2022-48361

The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in r…

No fix yet
Fix from $1,600 2023-03-27
Pgadmin 4 MEDIUM 6.5
CVE-2023-0241EPSS 9%

pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the…

Fix: 6.19+
Fix from $1,600 2023-03-27
Infrasuite Device Master CRITICAL 9.8
CVE-2023-1142

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and …

Fix: 1.0.5+
Fix from $2,300 2023-03-27
Infrasuite Device Master HIGH 8.8
CVE-2023-1134

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to r…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Scriptcase MEDIUM 6.5
CVE-2022-32199

db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file para…

Fix: after 9.9.008
Fix from $1,600 2023-03-27
Dcbi Netlog Lab Firmware CRITICAL 9.8
CVE-2023-26802EPSS 49%

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication…

No fix yet
Fix from $2,300 2023-03-26
Ptzapp 2 HIGH 7.5
CVE-2023-27055

Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.

Fix: 2.0.1051.53+
Fix from $1,950 2023-03-24
Mlflow CRITICAL 9.8
CVE-2023-1177EPSS 70%

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

Fix: 2.2.1+
Fix from $2,300 2023-03-24