Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Ios Xe MEDIUM 6.5
CVE-2023-20066

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access reso…

Mitigation only
Fix from $1,600 2023-03-23
Control For Beaglebone HIGH 8.8
CVE-2018-25048

The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify a…

Fix: 3.5.12.30+
Fix from $1,950 2023-03-23
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2023-25688

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An at…

Patch available
Fix from $1,600 2023-03-22
Thinmanager CRITICAL 9.8
CVE-2023-27855EPSS 13%

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at…

Fix: after 12.1.5
Fix from $2,300 2023-03-22
Thinmanager HIGH 7.5
CVE-2023-27856EPSS 77%

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticat…

Fix: after 12.1.5
Fix from $1,950 2023-03-22
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2023-25689

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An …

Patch available
Fix from $1,600 2023-03-21
Custom Reports HIGH 8.8
CVE-2023-27981

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Student Study Center Desk Management System CRITICAL 9.8
CVE-2023-1467

A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown funct…

Mitigation only
Fix from $2,300 2023-03-17
Android MEDIUM 5.5
CVE-2023-21456

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

Mitigation only
Fix from $1,600 2023-03-16
Go Huge Util HIGH 8.8
CVE-2023-28105

go-used-util has commonly used utility functions for Go. Versions prior to 0.0.34 have a ZipSlip issue when using fsutil package to unzip files. When…

Fix: 0.0.34+
Fix from $1,950 2023-03-16
Swig Templates HIGH 7.5
CVE-2023-25345

Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or exten…

Fix: after 2.0.4
Fix from $1,950 2023-03-15
Roxy Wi MEDIUM 5.3
CVE-2023-25804

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulne…

Fix: 6.3.5.0+
Fix from $1,600 2023-03-15
Stellarium CRITICAL 9.8
CVE-2023-28371

In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.

Fix: after 1.2
Fix from $2,300 2023-03-15
Graphql Engine HIGH 7.5
CVE-2023-27588

Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL E…

Fix: 1.3.4 / 2.11.5+
Fix from $1,950 2023-03-14
Teacms HIGH 8.8
CVE-2023-1398

A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /ad…

No fix yet
Fix from $1,950 2023-03-14
Wp Go Maps MEDIUM 6.5
CVE-2022-47595

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15…

Fix: after 9.0.15
Fix from $1,600 2023-03-14
Netweaver Application Server Abap HIGH 8.1
CVE-2023-27500

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this att…

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap CRITICAL 9.6
CVE-2023-27501

SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to ex…

Mitigation only
Fix from $2,300 2023-03-14
Netweaver Application Server Abap CRITICAL 9.6
CVE-2023-27269

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows a…

Mitigation only
Fix from $2,300 2023-03-14
Roxy Wi HIGH 7.5
CVE-2023-25803

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerab…

Fix: 6.3.5.0+
Fix from $1,950 2023-03-13
Roxy Wi HIGH 7.5
CVE-2023-25802

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../…

Fix: 6.3.6.0+
Fix from $1,950 2023-03-13
Backupbuddy HIGH 7.5
CVE-2022-31474EPSS 64%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue …

Fix: 8.7.5.0+
Fix from $1,950 2023-03-13
Metersphere MEDIUM 6.5
CVE-2023-25814

metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI …

Fix: 2.7.1+
Fix from $1,600 2023-03-09
Help Desk CRITICAL 9.8
CVE-2021-33353

Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary c…

Fix: 1.3.7+
Fix from $2,300 2023-03-08
Enterprise Server HIGH 8.8
CVE-2023-23760

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To ex…

Fix: 3.4.17 / 3.5.14+
Fix from $1,950 2023-03-08
Goutil HIGH 8.8
CVE-2023-27475

Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files …

Fix: 0.6.0+
Fix from $1,950 2023-03-07
Fortios HIGH 7.1
CVE-2022-41328 KEVEPSS 12%

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2…

Fix: 6.2.14 / 6.4.12+
Fix from $1,950 2023-03-07
Fortiproxy HIGH 8.2
CVE-2022-42476

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy v…

Fix: after 7.2.3
Fix from $1,950 2023-03-07