Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-37601
Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.
Office Suite
No fix yet
HIGH 7.5
CVE-2023-31461
Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled…
Gg
No fix yet
MEDIUM 6.5
CVE-2023-2913
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This featur…
Thinmanager
after 13.0.2
HIGH 7.8
CVE-2023-37476
OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrar…
Openrefine
after 3.7.3
CRITICAL 9.8
CVE-2023-37461
Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../…
Metersphere
2.10.3+
MEDIUM 6.5
CVE-2023-37781
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.
Emqx
No fix yet
HIGH 7.5
CVE-2023-38337
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that i…
Rswag
2.10.1+
HIGH 7.5
CVE-2023-37474EPSS 45%
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path…
Copyparty
1.8.2+
HIGH 7.5
CVE-2023-35069
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal.
This issue affects B…
Bullwark Momentum Series
Mitigation only
MEDIUM 6.5
CVE-2023-34135
Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file s…
Analytics
9.3.2+
HIGH 8.8
CVE-2023-34129EPSS 41%
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated r…
Analytics
9.3.2+
MEDIUM 6.5
CVE-2023-34125EPSS 25%
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root p…
Analytics
9.3.2+
CRITICAL 9.8
CVE-2023-26564
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated…
Ej2 Aspcore File Provider
No fix yet
CRITICAL 9.8
CVE-2023-26563
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can…
Nodejs File System Provider
No fix yet
MEDIUM 6.5
CVE-2023-37960
Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jen…
Mathworks Polyspace
after 1.0.5
MEDIUM 6.5
CVE-2023-22887
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende…
Airflow
2.6.3+
MEDIUM 6.5
CVE-2023-25606
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management…
Fortianalyzer
6.4.12 / 7.2.2+
HIGH 7.5
CVE-2022-23447
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0…
Fortiextender Firmware
3.2.4 / 3.3.3+
HIGH 8.1
CVE-2023-33989
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal…
Netweaver Bi Content
Mitigation only
MEDIUM 5.5
CVE-2023-1183EPSS 65%
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the content…
Fedora
7.4.6+
HIGH 7.5
CVE-2023-37288
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this v…
Smartbpm.net
Mitigation only
CRITICAL 9.9
CVE-2023-36460EPSS 40%
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, …
Mastodon
3.5.9 / 4.0.5+
MEDIUM 6.5
CVE-2023-23547
A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network re…
Ur32l Firmware
No fix yet
HIGH 7.5
CVE-2023-23907
A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead…
Milesightvpn
No fix yet
HIGH 8.1
CVE-2020-21862
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
Duxcms
No fix yet
MEDIUM 5.5
CVE-2023-30678
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
Calendar
12.4.07.15+
HIGH 7.8
CVE-2023-24256
An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.
Aspen
3.3.0+
HIGH 7.5
CVE-2023-36827
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…
Fides
2.15.1+
HIGH 8.1
CVE-2023-36822
Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to…
Uptime Kuma
1.22.1+
HIGH 8.1
CVE-2023-35975
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in …
Arubaos
8.6.0.21 / 8.10.0.7+