Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.1 CVE-2023-5241 The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload… Wpbot 4.9.1+ Fix from $1,9502023-10-19 HIGH 7.1 CVE-2023-43801 Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way … Create Agent 1.3.3+ Fix from $1,9502023-10-18 HIGH 7.8 CVE-2023-43802 Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with th… Create Agent 1.3.3+ Fix from $1,9502023-10-18 HIGH 7.1 CVE-2023-43803 Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way … Create Agent 1.3.3+ Fix from $1,9502023-10-18 HIGH 7.5 CVE-2023-45383 In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal informat… Sonice Etiquetage after 2.5.9 Fix from $1,9502023-10-18 HIGH 7.5 CVE-2023-39331 A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises becau… Node.js 20.8.1+ Fix from $1,9502023-10-18 CRITICAL 9.8 CVE-2023-39332 Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the… Node.js 20.8.0+ Fix from $2,3002023-10-18 MEDIUM 6.5 CVE-2023-34208 Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arb… Mailhunter Ultimate after 2023 Fix from $1,6002023-10-17 HIGH 7.5 CVE-2023-43121 A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and befor… Exos 22.7 / 31.7.2+ Fix from $1,9502023-10-16 HIGH 7.2 CVE-2023-45686 Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenti… Titan Mfp Server 2.0.18+ Fix from $1,9502023-10-16 MEDIUM 6.5 CVE-2023-45689 Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacke… Titan Mft Server 2.0.18+ Fix from $1,6002023-10-16 CRITICAL 9.1 CVE-2023-45685 Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows … Titan Mft Server 2.0.18+ Fix from $2,3002023-10-16 HIGH 8.1 CVE-2023-21415 Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to path traversal attacks that all… Axis Os 6.50.5.2 / 6.50.5.14+ Fix from $1,9502023-10-16 MEDIUM 5.3 CVE-2023-5588 A vulnerability was found in kphrx pleroma. It has been classified as problematic. This affects the function Pleroma.Emoji.Pack of the file lib/plero… Pleroma Patch available Fix from $1,6002023-10-15 HIGH 7.5 CVE-2023-38312 A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary file… Counter Strike Mitigation only Fix from $1,9502023-10-15 HIGH 7.5 CVE-2022-33165 IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted U… Security Directory Integrator Patch available Fix from $1,9502023-10-14 HIGH 7.5 CVE-2023-45855 qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI. Qdpm No fix yet Fix from $1,9502023-10-14 HIGH 7.5 CVE-2023-32974 A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users … Qts 5.1.0.2444+ Fix from $1,9502023-10-13 HIGH 7.5 CVE-2023-41682 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 thr… Fortisandbox after 4.2.5 Fix from $1,9502023-10-13 HIGH 7.5 CVE-2023-4990 Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files. Espeak Ng 1.52.0 / 4.6.0.30210+ Fix from $1,9502023-10-11 CRITICAL 9.9 CVE-2023-41373 A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BI… Big Ip Access Policy Manager 14.1.5.6 / 15.1.10.2+ Fix from $2,3002023-10-10 HIGH 8.8 CVE-2023-42796 A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11). Th… Cp 8050 Firmware 05.11+ Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-45352 Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the… Unify Openscape Common Management Mitigation only Fix from $1,9502023-10-09 HIGH 7.8 CVE-2023-36123 Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain… Plain Craft Launcher 2 No fix yet Fix from $1,9502023-10-07 MEDIUM 6.5 CVE-2023-23365 A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the… Music Station 5.3.22+ Fix from $1,6002023-10-06 MEDIUM 6.5 CVE-2023-23366 A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the… Music Station 5.3.22+ Fix from $1,6002023-10-06 MEDIUM 6.5 CVE-2023-43070 Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A remote authenticated attacker c… Smartfabric Storage Software 1.4.1+ Fix from $1,6002023-10-05 CRITICAL 9.8 CVE-2023-5399EPSS 39% A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on … Spacelogic C Bus Toolkit 1.16.4+ Fix from $2,3002023-10-04 HIGH 7.5 CVE-2023-3512 Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an… Conacwin after 3.8.2.2 Fix from $1,9502023-10-04 HIGH 8.8 CVE-2023-3701 Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non priv… Aqua Drive Mitigation only Fix from $1,9502023-10-04