Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-37601 Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts. Office Suite No fix yet Fix from $1,9502023-07-20 HIGH 7.5 CVE-2023-31461 Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled… Gg No fix yet Fix from $1,9502023-07-20 MEDIUM 6.5 CVE-2023-2913 An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This featur… Thinmanager after 13.0.2 Fix from $1,6002023-07-18 HIGH 7.8 CVE-2023-37476 OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrar… Openrefine after 3.7.3 Fix from $1,9502023-07-17 CRITICAL 9.8 CVE-2023-37461 Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../… Metersphere 2.10.3+ Fix from $2,3002023-07-17 MEDIUM 6.5 CVE-2023-37781 An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file. Emqx No fix yet Fix from $1,6002023-07-17 HIGH 7.5 CVE-2023-38337 rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that i… Rswag 2.10.1+ Fix from $1,9502023-07-14 HIGH 7.5 CVE-2023-37474EPSS 45% Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path… Copyparty 1.8.2+ Fix from $1,9502023-07-14 HIGH 7.5 CVE-2023-35069 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal. This issue affects B… Bullwark Momentum Series Mitigation only Fix from $1,9502023-07-13 MEDIUM 6.5 CVE-2023-34135 Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file s… Analytics 9.3.2+ Fix from $1,6002023-07-13 HIGH 8.8 CVE-2023-34129EPSS 41% Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated r… Analytics 9.3.2+ Fix from $1,9502023-07-13 MEDIUM 6.5 CVE-2023-34125EPSS 25% Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root p… Analytics 9.3.2+ Fix from $1,6002023-07-13 CRITICAL 9.8 CVE-2023-26564 The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated… Ej2 Aspcore File Provider No fix yet Fix from $2,3002023-07-12 CRITICAL 9.8 CVE-2023-26563 The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can… Nodejs File System Provider No fix yet Fix from $2,3002023-07-12 MEDIUM 6.5 CVE-2023-37960 Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jen… Mathworks Polyspace after 1.0.5 Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-22887 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende… Airflow 2.6.3+ Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-25606 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management… Fortianalyzer 6.4.12 / 7.2.2+ Fix from $1,6002023-07-11 HIGH 7.5 CVE-2022-23447 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0… Fortiextender Firmware 3.2.4 / 3.3.3+ Fix from $1,9502023-07-11 HIGH 8.1 CVE-2023-33989 An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal… Netweaver Bi Content Mitigation only Fix from $1,9502023-07-11 MEDIUM 5.5 CVE-2023-1183EPSS 65% A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the content… Fedora 7.4.6+ Fix from $1,6002023-07-10 HIGH 7.5 CVE-2023-37288 SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this v… Smartbpm.net Mitigation only Fix from $1,9502023-07-10 CRITICAL 9.9 CVE-2023-36460EPSS 40% Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, … Mastodon 3.5.9 / 4.0.5+ Fix from $2,3002023-07-06 MEDIUM 6.5 CVE-2023-23547 A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network re… Ur32l Firmware No fix yet Fix from $1,6002023-07-06 HIGH 7.5 CVE-2023-23907 A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead… Milesightvpn No fix yet Fix from $1,9502023-07-06 HIGH 8.1 CVE-2020-21862 Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del. Duxcms No fix yet Fix from $1,9502023-07-06 MEDIUM 5.5 CVE-2023-30678 Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file. Calendar 12.4.07.15+ Fix from $1,6002023-07-06 HIGH 7.8 CVE-2023-24256 An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal. Aspen 3.3.0+ Fix from $1,9502023-07-06 HIGH 7.5 CVE-2023-36827 Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem… Fides 2.15.1+ Fix from $1,9502023-07-05 HIGH 8.1 CVE-2023-36822 Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to… Uptime Kuma 1.22.1+ Fix from $1,9502023-07-05 HIGH 8.1 CVE-2023-35975 An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in … Arubaos 8.6.0.21 / 8.10.0.7+ Fix from $1,9502023-07-05