Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-6023 An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter. Modeldb No fix yet Fix from $1,9502023-11-16 HIGH 7.5 CVE-2023-6015 MLflow allowed arbitrary files to be PUT onto the server. Mlflow 2.8.1+ Fix from $1,9502023-11-16 CRITICAL 9.8 CVE-2023-5245 FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intend… Mleap Patch available Fix from $2,3002023-11-15 HIGH 7.5 CVE-2023-34062 In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a speciall… Reactor Netty 1.0.39 / 1.1.13+ Fix from $1,9502023-11-15 MEDIUM 5.3 CVE-2023-6032 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumerat… Galaxy Vl Firmware Mitigation only Fix from $1,6002023-11-15 MEDIUM 6.5 CVE-2023-5189 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy … Ansible Automation Platform No fix yet Fix from $1,6002023-11-14 HIGH 7.8 CVE-2023-33878 Path transversal in some Intel(R) NUC P14E Laptop Element Audio Install Package software before version 156 for Windows may allow an authenticated us… Audio Install Package 1.0.0.156+ Fix from $1,9502023-11-14 HIGH 7.3 CVE-2023-32655 Path transversal in some Intel(R) NUC Kits & Mini PCs - NUC8i7HVK & NUC8HNK USB Type C power delivery controller installatio software before version … Usb Type C Power Delivery Controller 1.0.10.3+ Fix from $1,9502023-11-14 HIGH 7.3 CVE-2023-32278 Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installati… Nuc Uniwill Service Driver 1.0.1.7+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-24592 Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable e… Advisor 2023.1+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2022-27229 Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authe… Hdmi Firmware 1.79.1.1+ Fix from $1,9502023-11-14 HIGH 7.2 CVE-2023-45880 GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The… Gibbon after 25.0.00 Fix from $1,9502023-11-14 CRITICAL 9.8 CVE-2023-47246 KEVEPSS 99% In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as… Sysaid 23.3.36+ Fix from $2,3002023-11-10 HIGH 7.5 CVE-2023-45283 The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equiv… Go 1.20.11 / 1.21.4+ Fix from $1,9502023-11-09 HIGH 8.8 CVE-2023-40055 The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-leve… Network Configuration Manager after 2023.4 Fix from $1,9502023-11-09 HIGH 8.8 CVE-2023-40054 The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-leve… Network Configuration Manager after 2023.4 Fix from $1,9502023-11-09 HIGH 7.1 CVE-2023-47613 A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion E… Bgs5 Firmware Mitigation only Fix from $1,9502023-11-09 HIGH 7.5 CVE-2023-36667 Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal. Couchbase Server 7.1.5+ Fix from $1,9502023-11-08 HIGH 7.2 CVE-2023-46253 Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the back… Squidex No fix yet Fix from $1,9502023-11-07 HIGH 8.1 CVE-2023-5355 The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter … Awesome Support 6.1.5+ Fix from $1,9502023-11-06 HIGH 7.5 CVE-2023-39299 A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of u… Music Station 4.8.11 / 5.1.16+ Fix from $1,9502023-11-03 CRITICAL 9.8 CVE-2023-3961 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory… Storage 4.17.12 / 4.18.8+ Fix from $2,3002023-11-03 HIGH 7.5 CVE-2023-41344 NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl… Mobile Device Manager Mitigation only Fix from $1,9502023-11-03 MEDIUM 6.5 CVE-2023-41356 NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl… Tronclass Ilearn Mitigation only Fix from $1,6002023-11-03 HIGH 7.5 CVE-2023-34260EPSS 73% Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a dire… D Copia253mf Plus Firmware after 2vg_s000.002.561 Fix from $1,9502023-11-03 HIGH 8.8 CVE-2023-20220 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remo… Secure Firewall Management Center after 7.3.1.1 Fix from $1,9502023-11-01 HIGH 8.8 CVE-2023-33226 The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-leve… Network Configuration Manager 2023.4+ Fix from $1,9502023-11-01 HIGH 8.8 CVE-2023-33227 The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level … Network Configuration Manager 2023.4+ Fix from $1,9502023-11-01 MEDIUM 6.5 CVE-2023-2621 The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This v… Modular Advanced Control For Hvdc 7.17.0.0+ Fix from $1,6002023-11-01 MEDIUM 5.3 CVE-2023-46237 FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited en… Fogproject 1.5.10+ Fix from $1,6002023-10-31