Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-49294EPSS 46% Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certi… Asterisk 18.20.1 / 20.5.1+ Fix from $1,9502023-12-14 HIGH 7.5 CVE-2023-48660 Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerabil… Solutions Enabler Virtual Appliance 9.2.4.5 / 9.2.4.7+ Fix from $1,9502023-12-14 MEDIUM 6.7 CVE-2023-44278 Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high priv… Powerprotect Data Protection 2.7.6 / 6.2.1.110+ Fix from $1,6002023-12-14 HIGH 7.1 CVE-2023-6407 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletio… Easy Ups Online Monitoring Software 2.6-ga-01-23248+ Fix from $1,9502023-12-14 HIGH 8.8 CVE-2023-43586 Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct … Meeting Software Development Kit 5.14.14 / 5.15.12+ Fix from $1,9502023-12-13 MEDIUM 6.5 CVE-2023-47624 Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to … Audiobookshelf after 2.4.3 Fix from $1,6002023-12-13 HIGH 8.8 CVE-2023-44251 ** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet Fo… Fortiwan Mitigation only Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-6753 Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. Mlflow 2.9.2+ Fix from $1,9502023-12-13 MEDIUM 6.5 CVE-2023-49089 Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users … Umbraco Cms 8.18.10 / 10.8.1+ Fix from $1,6002023-12-12 HIGH 7.5 CVE-2023-28465 The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain dire… Hl7 Fhir Core 5.6.106+ Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-46455EPSS 47% In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file … Gl Ar300m Firmware Mitigation only Fix from $1,9502023-12-12 HIGH 8.8 CVE-2023-45316 Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing a… Mattermost Server after 9.2.1 Fix from $1,9502023-12-12 MEDIUM 5.3 CVE-2023-49058 SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus … Master Data Governance Mitigation only Fix from $1,6002023-12-12 MEDIUM 6.5 CVE-2023-36654 Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host serv… Cryptospike No fix yet Fix from $1,6002023-12-12 HIGH 7.5 CVE-2023-50449 JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter. Jfinalcms No fix yet Fix from $1,9502023-12-10 MEDIUM 5.3 CVE-2023-46493 Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted… Evershop Mitigation only Fix from $1,6002023-12-08 HIGH 8.3 CVE-2023-46496 Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted… Evershop Mitigation only Fix from $1,9502023-12-08 MEDIUM 5.4 CVE-2023-46497 Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted… Evershop Mitigation only Fix from $1,6002023-12-08 HIGH 7.2 CVE-2023-49788 Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the B… Richdocumentscode 23.5.602+ Fix from $1,9502023-12-08 MEDIUM 6.5 CVE-2023-47440 Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticat… Gladys Assistant 4.30.0+ Fix from $1,6002023-12-07 HIGH 7.5 CVE-2023-33411 A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 b… M11sdv 4c Ln4f Firmware after 3.17.02 Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-46307 An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while… Etcd Browser Mitigation only Fix from $1,9502023-12-07 CRITICAL 9.8 CVE-2023-6458 Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver… Mattermost Server 7.8.14 / 8.1.5+ Fix from $2,3002023-12-06 MEDIUM 6.5 CVE-2023-5105 The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and d… Frontend File Manager Plugin 22.6+ Fix from $1,6002023-12-04 MEDIUM 6.5 CVE-2023-44306 Dell DM5500 contains a path traversal vulnerability in the appliance. A remote attacker with high privileges could potentially exploit this vulnerabi… Dm5500 Firmware after 5.14.0.0 Fix from $1,6002023-12-04 HIGH 8.8 CVE-2023-49108 Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, … Rakrak Document Plus 6.1.1.3a+ Fix from $1,9502023-12-04 HIGH 7.5 CVE-2018-25094 A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown pro… Online Accounting System 2.0.0+ Fix from $1,9502023-12-03 HIGH 7.5 CVE-2023-47279 In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information th… Infrasuite Device Master Mitigation only Fix from $1,9502023-11-30 HIGH 7.5 CVE-2023-49735 ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML… Tiles Mitigation only Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-46690 In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the fil… Infrasuite Device Master Mitigation only Fix from $1,9502023-11-30