Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Flatpress CRITICAL 9.8
CVE-2023-0947

Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: after 1.2.1
Fix from $2,300 2023-02-22
Borg MEDIUM 5.3
CVE-2023-26265

The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preproces…

Fix: 1.1.19+
Fix from $1,600 2023-02-21
Infosphere Information Server HIGH 7.5
CVE-2023-24960

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…

Patch available
Fix from $1,950 2023-02-17
Enterprise Server MEDIUM 6.5
CVE-2023-22380

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To e…

Fix: 3.7.6+
Fix from $1,600 2023-02-16
Quartus Prime HIGH 7.8
CVE-2022-33892

Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of pr…

Fix: 22.1 / 22.2+
Fix from $1,950 2023-02-16
Fortiweb MEDIUM 6.5
CVE-2023-23778

A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow …

Fix: after 6.3.21
Fix from $1,600 2023-02-16
Fortiweb MEDIUM 6.5
CVE-2023-23784

A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows a…

Fix: 6.3.21 / 7.0.3+
Fix from $1,600 2023-02-16
Fortiswitchmanager HIGH 8.1
CVE-2022-41335

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy v…

Fix: after 7.0.8
Fix from $1,950 2023-02-16
Fortiweb MEDIUM 6.5
CVE-2022-30300

A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated a…

Fix: 6.3.19+
Fix from $1,600 2023-02-16
Netmodule Router Software HIGH 8.8
CVE-2023-0862

The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploadi…

Fix: 4.3.0.119 / 4.4.0.118+
Fix from $1,950 2023-02-16
Orion Platform HIGH 7.8
CVE-2022-47506

SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account …

Mitigation only
Fix from $1,950 2023-02-15
Git HIGH 7.5
CVE-2023-23946

Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.3…

Fix: 2.30.8 / 2.31.7+
Fix from $1,950 2023-02-14
Titan Ftp Server HIGH 8.8
CVE-2023-22629EPSS 12%

An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authent…

Fix: after 1.94.1205
Fix from $1,950 2023-02-14
Ureport CRITICAL 9.1
CVE-2023-24188

ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

Mitigation only
Fix from $2,300 2023-02-13
Sunflower CRITICAL 9.8
CVE-2022-48323EPSS 57%

Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated a…

No fix yet
Fix from $2,300 2023-02-13
Glance MEDIUM 6.5
CVE-2022-25937

Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. …

Fix: 3.0.9+
Fix from $1,600 2023-02-13
Vert.x Web MEDIUM 5.3
CVE-2023-24815

Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vertx web applications that serve…

Fix: 4.3.8+
Fix from $1,600 2023-02-09
Yugabytedb Managed CRITICAL 9.8
CVE-2023-0745

The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path trav…

Fix: after 2.13
Fix from $2,300 2023-02-09
Adminlte CRITICAL 9.8
CVE-2021-36471

Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/ind…

Mitigation only
Fix from $2,300 2023-02-07
Gin Vue Admin HIGH 7.5
CVE-2022-47762

In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.

Fix: 2.5.5+
Fix from $1,950 2023-02-03
Rt Ac68u Firmware CRITICAL 9.1
CVE-2021-37317

Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write ar…

Fix: 3.0.0.4.386.41634+
Fix from $2,300 2023-02-03
Phpwcms MEDIUM 5.4
CVE-2021-36425

Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $file parameter to unlink method …

Fix: 1.9.26+
Fix from $1,600 2023-02-03
Fedora MEDIUM 5.5
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACL…

Fix: 116+
Fix from $1,600 2023-02-02
Dotcms MEDIUM 6.5
CVE-2022-45783EPSS 8%

An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote C…

Fix: after 22.10.1
Fix from $1,600 2023-02-01
Lmxcms MEDIUM 6.5
CVE-2023-23136

lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.

No fix yet
Fix from $1,600 2023-02-01
Orangescrum HIGH 8.1
CVE-2023-0454

OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the ap…

No fix yet
Fix from $1,950 2023-02-01
Fast Checkin HIGH 7.5
CVE-2022-47768

Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.

No fix yet
Fix from $1,950 2023-02-01
Application Server MEDIUM 5.3
CVE-2016-15023

A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affects an unknown part of the fil…

Fix: 6.6.7+
Fix from $1,600 2023-01-31
Identityiq HIGH 7.5
CVE-2022-46835

IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentityIQ 8.1 and all 8.1 patch leve…

Mitigation only
Fix from $1,950 2023-01-31
Ubi Reader MEDIUM 5.5
CVE-2023-0591

ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the attacker to overwrite files o…

Fix: 0.8.5+
Fix from $1,600 2023-01-31