Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-2880
Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal vulnerability of the web inter…
Frauscher Diagnostic System 101
after 1.3.3
MEDIUM 6.5
CVE-2023-36819
Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/re…
Knowage
8.1.8+
MEDIUM 5.5
CVE-2023-35946
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependen…
Gradle
7.6.2 / 8.2.0+
HIGH 8.1
CVE-2023-35947
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…
Gradle
7.6.2 / 8.2.0+
MEDIUM 6.5
CVE-2023-32608
Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticate…
Pleasanter
1.3.39.2+
HIGH 7.5
CVE-2023-33277
The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-travers…
Knx Ip Router Firmware
No fix yet
CRITICAL 9.8
CVE-2023-34598EPSS 47%
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation …
Gibbon
No fix yet
HIGH 7.5
CVE-2023-34843EPSS 7%
Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
Traggo
No fix yet
CRITICAL 9.1
CVE-2023-32623
Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the s…
Snow Monkey Forms
5.1.2+
MEDIUM 5.4
CVE-2023-3331
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG…
Aterm Wf300hp Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-19902
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
Wcms
No fix yet
CRITICAL 9.8
CVE-2023-30945
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated…
Clips2
0.24.10 / 0.111.2+
CRITICAL 9.1
CVE-2023-32521EPSS 67%
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote att…
Mobile Security
Patch available
HIGH 8.1
CVE-2023-32522
A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to d…
Mobile Security
Patch available
CRITICAL 9.8
CVE-2023-32557
A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary f…
Apex One
14.0.12105+
HIGH 7.5
CVE-2023-25306
MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal.
Multimc
0.7.0+
HIGH 7.8
CVE-2023-25307
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
Mrpack Install
0.16.3+
HIGH 7.5
CVE-2023-36301
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
Data Catalog
8.0-20230221+
HIGH 7.5
CVE-2023-36612
Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an attacker to write arbitrary f…
Basecamp
4.2.1+
CRITICAL 9.8
CVE-2023-35169
PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsa…
Php Imap
5.3.0+
HIGH 8.1
CVE-2023-35801
A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based …
Fme Server
2022.2.5+
CRITICAL 9.8
CVE-2023-34939EPSS 5%
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ash…
Onlyoffice
12.5.2+
HIGH 7.5
CVE-2023-35843EPSS 9%
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the serve…
Nocodb
after 0.106.1
HIGH 7.5
CVE-2023-35852
In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trig…
Suricata
6.0.13+
HIGH 7.5
CVE-2023-35844EPSS 6%
packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that …
Lightdash
0.510.3+
MEDIUM 6.5
CVE-2023-35840
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
Elfinder
2.1.62+
HIGH 7.5
CVE-2023-34645
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Jfinal Cms
No fix yet
CRITICAL 9.8
CVE-2023-34880
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vu…
Cmseasy
No fix yet
HIGH 7.8
CVE-2023-2270
The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute comman…
Netskope
100+
CRITICAL 9.8
CVE-2023-34865
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
Ujcms
No fix yet