Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-49801 Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` an… Lif Auth Server 1.4.0+ Fix from $1,9502024-01-12 HIGH 7.5 CVE-2010-10011 A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation le… Femitter Server No fix yet Fix from $1,9502024-01-12 HIGH 8.8 CVE-2023-31036 NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --m… Triton Inference Server 2.40+ Fix from $1,9502024-01-12 CRITICAL 9.8 CVE-2023-49569 A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files acro… Go Git 5.11.0+ Fix from $2,3002024-01-12 HIGH 7.2 CVE-2023-6583 The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via … Import And Export Users And Customers after 1.24.2 Fix from $1,9502024-01-11 HIGH 8.7 CVE-2023-5504 The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the Log File Folder. This allows a… Backwpup after 4.0.1 Fix from $1,9502024-01-11 HIGH 7.5 CVE-2023-6699 The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.3… Wp Compress after 6.10.33 Fix from $1,9502024-01-11 HIGH 7.5 CVE-2023-51127 FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerabil… Flir Ax8 Firmware Mitigation only Fix from $1,9502024-01-10 HIGH 7.2 CVE-2023-50916 Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a U… Device Manager 3.1.1213.0+ Fix from $1,9502024-01-10 MEDIUM 6.5 CVE-2023-37932 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and be… Fortivoice 6.4.8+ Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-48249 The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application O… Nexo Os after 1500-sp2 Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-48246 The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root… Nexo Os after 1500-sp2 Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-48242 The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application… Nexo Os after 1500-sp2 Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-48243 The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”)… Nexo Os after 1500-sp2 Fix from $1,9502024-01-10 HIGH 7.5 CVE-2024-0354 A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processi… Download Station after 1.1.8 Fix from $1,9502024-01-10 HIGH 7.5 CVE-2024-0341 A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/cont… Inis after 2.0.1 Fix from $1,9502024-01-09 HIGH 8.8 CVE-2023-47890 pyLoad 0.5.0 is vulnerable to Unrestricted File Upload. Pyload Mitigation only Fix from $1,9502024-01-08 HIGH 8.6 CVE-2023-47211EPSS 47% A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can le… Manageengine Firewall Analyzer 12.7+ Fix from $1,9502024-01-08 HIGH 7.5 CVE-2024-22050 Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public fold… Iodine after 0.7.33 Fix from $1,9502024-01-04 MEDIUM 6.5 CVE-2023-29962 S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability. S Cms No fix yet Fix from $1,6002024-01-04 MEDIUM 5.5 CVE-2024-20804 Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in A… Android 14.5.00.21+ Fix from $1,6002024-01-04 MEDIUM 5.5 CVE-2024-20805 Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Andr… Android 14.5.00.21+ Fix from $1,6002024-01-04 HIGH 7.8 CVE-2024-21633 Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to the… Apktool 2.9.2+ Fix from $1,9502024-01-03 HIGH 7.5 CVE-2023-37607 Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.… Soc Fl9600 Firstlane Firmware No fix yet Fix from $1,9502024-01-03 HIGH 7.5 CVE-2023-47473 Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted … Ifair after 23.8_ad0 Fix from $1,9502024-01-03 CRITICAL 9.8 CVE-2023-45722 HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is … Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-45723 HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate … Dryice Myxalytics Mitigation only Fix from $2,3002024-01-03 HIGH 7.8 CVE-2023-41780 There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker co… Zxcloud Irai 7.23.32+ Fix from $1,9502024-01-03 HIGH 8.8 CVE-2023-7114 Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server. Mattermost 2.10.1+ Fix from $1,9502023-12-29 MEDIUM 5.4 CVE-2023-52085EPSS 30% Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value… Winter 1.2.4+ Fix from $1,6002023-12-29