Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2015-5467
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
Yii
2.0.5+
MEDIUM 6.8
CVE-2023-40930
An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.
Skyworth Os
No fix yet
MEDIUM 6.5
CVE-2022-45447
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not p…
M4 Pdf
after 3.2.3
MEDIUM 5.5
CVE-2023-43616
An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.
Croc
after 9.6.5
MEDIUM 5.3
CVE-2023-41599EPSS 11%
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
Jfinalcms
No fix yet
CRITICAL 9.8
CVE-2022-28357
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
Nats Server
after 2.7.4
MEDIUM 6.5
CVE-2023-37739
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
I Doit
after 25
MEDIUM 6.5
CVE-2023-39916
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability…
Routinator
0.12.2+
HIGH 7.5
CVE-2023-4914
Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.
Cecil
7.47.1+
HIGH 7.5
CVE-2023-32558
The use of the deprecated API `process.binding()` can bypass the permission model through path traversal.
This vulnerability affects all users usin…
Node.js
20.5.1+
HIGH 7.8
CVE-2023-35670
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path travers…
Android
Patch available
HIGH 7.5
CVE-2023-38256
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3
vulnerable to a path trav…
Maglink Lx Web Console Configuration
Mitigation only
CRITICAL 9.1
CVE-2022-33164
IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted U…
Security Directory Server
Patch available
HIGH 7.5
CVE-2023-41578
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Jeecg Boot
after 3.5.3
HIGH 7.8
CVE-2023-4782
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. …
Terraform
1.5.7+
HIGH 7.5
CVE-2023-40924
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
Solarview Compact Firmware
6.0+
HIGH 7.5
CVE-2023-39584EPSS 32%
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
Hexo
after 6.3.0
HIGH 7.8
CVE-2021-28644
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Path travers…
Acrobat
17.011.30199 / 20.004.30006+
HIGH 7.8
CVE-2021-35980
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Path travers…
Acrobat
17.011.30199 / 20.004.30006+
MEDIUM 5.5
CVE-2023-4480
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request th…
Phpfusion
after 9.10.30
HIGH 8.8
CVE-2023-39448
Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, …
Shirasagi
1.18.0+
HIGH 7.5
CVE-2023-4748
A vulnerability, which was classified as critical, has been found in Yongyou UFIDA-NC up to 20230807. This issue affects some unknown processing of t…
Ufida Nc
No fix yet
MEDIUM 5.5
CVE-2023-41057
hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern from the configuration file.…
Hyper Bump It
0.5.1+
CRITICAL 9.8
CVE-2023-4614
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…
Lg Led Assistant
Mitigation only
HIGH 7.5
CVE-2023-4615
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…
Lg Led Assistant
Mitigation only
HIGH 7.5
CVE-2023-4616
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…
Lg Led Assistant
Mitigation only
CRITICAL 9.8
CVE-2023-4613
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…
Lg Led Assistant
Mitigation only
MEDIUM 6.5
CVE-2023-41747
Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Cloud Manager (Windows) before b…
Cloud Manager
6.2.23089.203+
HIGH 8.1
CVE-2023-31167
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering Laboratories SEL-5036 acSELera…
Sel 5036 Acselerator Bay Screen Builder
1.0.49152.778+
HIGH 7.8
CVE-2023-39138
An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.
Zipfoundation
No fix yet