Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 8.8 CVE-2023-38708 Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist… Pimcore 10.6.7+ Fix from $1,9502023-08-04 HIGH 7.5 CVE-2023-38950 KEVEPSS 85% A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a cr… Biotime 9.0.1+ Fix from $1,9502023-08-03 CRITICAL 9.8 CVE-2023-38951 ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server vi… Biotime Mitigation only Fix from $2,3002023-08-03 HIGH 7.5 CVE-2023-0956 External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special … Telwin Scada Webinterface 6.2 / 7.2+ Fix from $1,9502023-08-03 HIGH 7.2 CVE-2023-35081 KEVEPSS 64% A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated admini… Endpoint Manager Mobile 11.8.1.2 / 11.9.1.2+ Fix from $1,9502023-08-03 HIGH 7.5 CVE-2023-33365 A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the ser… Biostar 2 2.9.1+ Fix from $1,9502023-08-03 MEDIUM 5.7 CVE-2023-3348 The Wrangler command line tool  (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local deve… Wrangler 3.1.1+ Fix from $1,6002023-08-03 MEDIUM 6.5 CVE-2022-26838 Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-… Remote Service Manager Mitigation only Fix from $1,6002023-08-03 HIGH 7.5 CVE-2023-38956 A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payloa… Bioaccess Ivs Mitigation only Fix from $1,9502023-08-03 CRITICAL 9.1 CVE-2023-33369 A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem,… Control Id Idsecure after 4.7.26.0 Fix from $2,3002023-08-03 MEDIUM 6.5 CVE-2023-3329 SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite fi… Scadawebserver after 2.08 Fix from $1,6002023-08-02 MEDIUM 5.5 CVE-2023-26441 Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi… Open Xchange Appsuite Office 8.11+ Fix from $1,6002023-08-02 MEDIUM 6.5 CVE-2023-3385 An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting from 16.1 before 16.1.3, all ve… GitLab 16.0.8 / 16.1.3+ Fix from $1,6002023-08-02 HIGH 7.8 CVE-2023-31427 Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with knowledge of full path names in… Fabric Operating System 9.1.1c+ Fix from $1,9502023-08-01 MEDIUM 5.3 CVE-2022-42182 Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal. Spectrum Spatial Analyst Patch available Fix from $1,6002023-07-31 MEDIUM 6.5 CVE-2023-35016 IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a s… Security Verify Governance Mitigation only Fix from $1,6002023-07-31 HIGH 7.5 CVE-2023-37218 Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Aeonix Mitigation only Fix from $1,9502023-07-30 HIGH 7.5 CVE-2020-22623 Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information. Jreport Mitigation only Fix from $1,9502023-07-27 HIGH 7.2 CVE-2023-23842 The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administr… Network Configuration Monitor 2023.3.0+ Fix from $1,9502023-07-26 HIGH 7.5 CVE-2022-31457 RTX TRAP v1.0 allows attackers to perform a directory traversal via a crafted request sent to the endpoint /data/. Rtx Trap Mitigation only Fix from $1,9502023-07-25 MEDIUM 6.5 CVE-2022-46900 An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Repor… Report Server after 5.8.0.135 Fix from $1,6002023-07-25 HIGH 7.5 CVE-2022-46902 An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report… Report Server after 5.8.0.135 Fix from $1,9502023-07-25 CRITICAL 9.8 CVE-2023-37460 Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API… Plexus Archiver 4.8.0+ Fix from $2,3002023-07-25 CRITICAL 9.8 CVE-2022-46898 An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vo… Report Server after 5.8.0.135 Fix from $2,3002023-07-25 MEDIUM 5.3 CVE-2023-33777 An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack. Amazon 5.2.24+ Fix from $1,6002023-07-25 CRITICAL 9.8 CVE-2023-26045 NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s… Nodebb 2.8.7+ Fix from $2,3002023-07-24 CRITICAL 9.8 CVE-2023-34478 Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth… Shiro 1.12.0+ Fix from $2,3002023-07-24 MEDIUM 5.5 CVE-2023-38633 A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local … Fedora 2.46.6 / 2.48.11+ Fix from $1,6002023-07-22 HIGH 7.5 CVE-2023-3813 The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for… Jupiter X Core after 2.5.0 Fix from $1,9502023-07-21 HIGH 7.5 CVE-2023-30200 In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop,… Ultimateimagetool 2.1.03+ Fix from $1,9502023-07-20