Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-26152 All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function … Static Server after 3.0.0 Fix from $1,9502023-10-03 MEDIUM 5.7 CVE-2023-43627 Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent au… Acera 1310 Firmware after 01.26 Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-5327 A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic. Affected by this issue is some unknown functionality… Cl4nx J Plus Firmware Mitigation only Fix from $1,6002023-10-01 HIGH 8.8 CVE-2022-35908 Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. Enterprise Wi Fi 6.4.2+ Fix from $1,9502023-09-29 MEDIUM 5.7 CVE-2023-5257 A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFil… Jndiexploit No fix yet Fix from $1,6002023-09-29 HIGH 8.6 CVE-2023-43662EPSS 8% ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without au… Shokoserver after 4.2.2 Fix from $1,9502023-09-28 HIGH 7.5 CVE-2023-43044 IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL reque… License Metric Tool 9.2.33+ Fix from $1,9502023-09-28 CRITICAL 9.8 CVE-2023-44169 SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php. Seacms No fix yet Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-44170 SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php. Seacms No fix yet Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-44171 SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php. Seacms No fix yet Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-44172 SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php. Seacms No fix yet Fix from $2,3002023-09-27 HIGH 7.8 CVE-2023-43825 Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arbitrary code by having a legit… Shihonkanri Plus after 9.0.3 Fix from $1,9502023-09-27 HIGH 8.8 CVE-2023-42819 JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Temp… Jumpserver 3.6.5+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-43216 SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php. Seacms No fix yet Fix from $2,3002023-09-27 CRITICAL 9.1 CVE-2023-42462 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $2,3002023-09-27 HIGH 7.5 CVE-2023-42487 Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Soundminer 2.01+ Fix from $1,9502023-09-27 CRITICAL 9.6 CVE-2023-42657EPSS 17% In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker could leverage this vulnerabilit… Ws Ftp Server 8.7.4 / 8.8.2+ Fix from $2,3002023-09-27 MEDIUM 5.4 CVE-2023-41888 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $1,6002023-09-27 HIGH 8.8 CVE-2023-2315 Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out ar… Opencart after 4.0.2.2 Fix from $1,9502023-09-27 HIGH 7.5 CVE-2022-4244 A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid… Integration Camel K 1.10.1 / 3.0.24+ Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-43382 Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the themePath in the uploade… Dreamer Cms Mitigation only Fix from $1,9502023-09-25 MEDIUM 6.5 CVE-2023-43256 A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a … Gladys Assistant after 4.26.1 Fix from $1,6002023-09-25 HIGH 7.5 CVE-2023-41302 Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perf… Emui No fix yet Fix from $1,9502023-09-25 CRITICAL 9.1 CVE-2023-39407 The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. Harmonyos No fix yet Fix from $2,3002023-09-25 MEDIUM 5.3 CVE-2023-5142 A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER… Gr 1100 P Firmware after 20230908 Fix from $1,6002023-09-24 HIGH 8.8 CVE-2023-38346 An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files … Vxworks Patch available Fix from $1,9502023-09-22 HIGH 7.5 CVE-2023-42280 mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not verify the incoming data, resu… Mee Admin No fix yet Fix from $1,9502023-09-21 HIGH 8.1 CVE-2023-42456 Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requir… Sudo 0.2.1+ Fix from $1,9502023-09-21 CRITICAL 9.8 CVE-2023-4760 In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. … Remote Application Platform after 3.25.0 Fix from $2,3002023-09-21 HIGH 7.5 CVE-2023-4152 Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal vulnerability of the web inte… Frauscher Diagnostic System 101 after 1.4.24 Fix from $1,9502023-09-21