Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Vocable Trainer MEDIUM 5.5
CVE-2017-20181

A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the fi…

Fix: 1.3.1+
Fix from $1,600 2023-03-07
Prism Launcher HIGH 7.8
CVE-2023-25304

An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file.

Fix: after 6.1
Fix from $1,950 2023-03-06
Fastcms HIGH 7.2
CVE-2023-1191

A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/TemplateController.java of the co…

No fix yet
Fix from $1,950 2023-03-06
\@nubosoftware\/node Static HIGH 7.5
CVE-2023-26111

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper …

No fix yet
Fix from $1,950 2023-03-06
Rakuraku Pc Cloud Agent CRITICAL 9.8
CVE-2023-22336

Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a …

Fix: after 13.0.0.40
Fix from $2,300 2023-03-06
Vigor 2960 Firmware MEDIUM 6.5
CVE-2023-1163

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul…

No fix yet
Fix from $1,600 2023-03-03
Financial Transaction Manager HIGH 7.5
CVE-2020-5001

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a s…

Fix: after 3.2.7
Fix from $1,950 2023-03-01
Kubernetes MEDIUM 6.5
CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g…

Fix: after 1.25.3
Fix from $1,600 2023-03-01
Drag And Drop Multiple File Upload Contact Form 7 CRITICAL 9.8
CVE-2023-1112

A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is …

Fix: 5.0.6.3+
Fix from $2,300 2023-03-01
Sd Wan MEDIUM 6.5
CVE-2023-22772

An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability res…

Fix: after 10.3.1.0
Fix from $1,600 2023-03-01
Arubaos MEDIUM 6.5
CVE-2023-22773

Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in …

Fix: after 10.3.1.0
Fix from $1,600 2023-03-01
Arubaos MEDIUM 6.5
CVE-2023-22774

Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in …

Fix: after 10.3.1.0
Fix from $1,600 2023-03-01
Go HIGH 7.5
CVE-2022-41722

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "…

Fix: 1.19.6+
Fix from $1,950 2023-02-28
Web Policy Agents CRITICAL 9.8
CVE-2023-0339

Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Managem…

Fix: after 5.10.1
Fix from $2,300 2023-02-28
Java Policy Agents CRITICAL 9.8
CVE-2023-0511

Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Manage…

Fix: after 5.10.1
Fix from $2,300 2023-02-28
Android HIGH 7.8
CVE-2023-20943

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could …

Patch available
Fix from $1,950 2023-02-28
Tornado HIGH 7.5
CVE-2023-25265

Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system.

Fix: 2.9.5+
Fix from $1,950 2023-02-28
Stagil Navigation HIGH 7.5
CVE-2023-26255EPSS 47%

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying …

Fix: 2.0.52+
Fix from $1,950 2023-02-28
Stagil Navigation HIGH 7.5
CVE-2023-26256EPSS 12%

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying …

Fix: 2.0.52+
Fix from $1,950 2023-02-28
Erp HIGH 7.5
CVE-2023-26758

Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.

No fix yet
Fix from $1,950 2023-02-27
Muyucms HIGH 8.8
CVE-2023-1044

A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file…

No fix yet
Fix from $1,950 2023-02-26
Muyucms HIGH 8.1
CVE-2023-1045

A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.p…

No fix yet
Fix from $1,950 2023-02-26
Manageengine Desktop Central HIGH 8.8
CVE-2022-48362EPSS 9%

Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A r…

Fix: 10.1.2137.2+
Fix from $1,950 2023-02-25
Vigor2960 Firmware MEDIUM 5.5
CVE-2023-1009EPSS 16%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function…

No fix yet
Fix from $1,600 2023-02-24
Muyucms MEDIUM 6.5
CVE-2023-1002

A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown processing of the file index.php…

No fix yet
Fix from $1,600 2023-02-24
Easybuilder Pro HIGH 7.8
CVE-2023-0104EPSS 22%

The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an …

Fix: 6.07.02.480 / 6.08.01.350+
Fix from $1,950 2023-02-22
Openemr HIGH 8.8
CVE-2023-22973

A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via th…

Fix: 7.0.0+
Fix from $1,950 2023-02-22
Nextcloud Server HIGH 7.5
CVE-2023-25579

Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and norm…

Fix: 20.0.14 / 21.0.9+
Fix from $1,950 2023-02-22
Cloudflow MEDIUM 6.5
CVE-2022-41216

Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.

Fix: 2.3.2+
Fix from $1,600 2023-02-22
Nvt Web Server HIGH 7.5
CVE-2023-23063

Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.

No fix yet
Fix from $1,950 2023-02-22