Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2023-42804 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an atta… Bigbluebutton after 2.5.18 Fix from $1,6002023-10-30 MEDIUM 6.5 CVE-2023-43648 baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data managem… Basercms 4.8.0+ Fix from $1,6002023-10-30 HIGH 7.5 CVE-2023-46863 Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST reque… Peppermint 0.2.4+ Fix from $1,9502023-10-30 MEDIUM 5.3 CVE-2023-46864 Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST req… Peppermint after 0.2.4 Fix from $1,6002023-10-30 CRITICAL 9.8 CVE-2005-10002 A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function… Secure Files 1.2+ Fix from $2,3002023-10-29 HIGH 7.5 CVE-2023-27170 Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter. Write Back Manager No fix yet Fix from $1,9502023-10-26 HIGH 8.8 CVE-2018-16739 An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus e… Tvip 10000 Firmware No fix yet Fix from $1,9502023-10-26 MEDIUM 6.5 CVE-2023-45867 ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker … Ilias No fix yet Fix from $1,6002023-10-26 HIGH 8.1 CVE-2023-45868 The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal a… Ilias No fix yet Fix from $1,9502023-10-26 HIGH 7.5 CVE-2023-30967 Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbit… Orbital Simulator 0.692.0+ Fix from $1,9502023-10-26 HIGH 7.5 CVE-2023-46346 In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest ca… Exportproducts 5.0.0+ Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-46119 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file wi… Parse Server 5.5.6 / 6.3.1+ Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-42488 EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Eisbaer Scada after 3.0.6433.1964 Fix from $1,9502023-10-25 HIGH 8.8 CVE-2023-37913 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prio… Xwiki 14.10.8 / 15.3+ Fix from $1,9502023-10-25 HIGH 8.8 CVE-2023-26578 Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root su… Idweb Mitigation only Fix from $1,9502023-10-25 HIGH 8.8 CVE-2022-38484 An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prio… Agevolt 0.1+ Fix from $1,9502023-10-25 MEDIUM 6.5 CVE-2022-38485 A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated at… Agevolt 0.1+ Fix from $1,6002023-10-25 HIGH 7.1 CVE-2023-46122 sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would h… Io 1.9.7+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2021-26736 Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low … Client Connector 3.6+ Fix from $1,9502023-10-23 MEDIUM 6.5 CVE-2021-46897 views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when … Codered Extensions 0.22.3+ Fix from $1,6002023-10-22 MEDIUM 6.5 CVE-2023-44256 A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and Forti… Fortianalyzer after 7.2.3 Fix from $1,6002023-10-20 HIGH 7.2 CVE-2023-5414 The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function.… Icegram Express after 5.6.23 Fix from $1,9502023-10-20 MEDIUM 6.5 CVE-2023-4274 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This all… Migration\, Backup\, Staging 0.9.90+ Fix from $1,6002023-10-20 HIGH 7.5 CVE-2023-45823 Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a secu… Hub 1.16.0+ Fix from $1,9502023-10-19 HIGH 7.5 CVE-2023-45277 Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escap… Yamcs Patch available Fix from $1,9502023-10-19 CRITICAL 9.1 CVE-2023-45278 Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP … Yamcs Patch available Fix from $2,3002023-10-19 MEDIUM 6.8 CVE-2023-35185 The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges. Access Rights Manager after 2023.2.0.73 Fix from $1,6002023-10-19 CRITICAL 9.8 CVE-2023-35187 The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated… Access Rights Manager after 2023.2.0.73 Fix from $2,3002023-10-19 MEDIUM 6.5 CVE-2023-31046 A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially a… Papercut Mf 22.1.1+ Fix from $1,6002023-10-19 HIGH 8.1 CVE-2023-5212 The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This m… Wpbot 4.9.1+ Fix from $1,9502023-10-19