Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-3241 A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/… Otcms after 6.62 Fix from $1,9502023-06-14 CRITICAL 9.8 CVE-2023-2278 The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' f… Wp Directory Kit 1.2.0+ Fix from $2,3002023-06-13 CRITICAL 9.1 CVE-2023-34342 AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances, which ma… Megarac Sp X 12.7 / 13.5+ Fix from $2,3002023-06-12 MEDIUM 6.5 CVE-2023-34345 AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lead to in… Megarac Sp X 12.7 / 13.5+ Fix from $1,6002023-06-12 HIGH 7.5 CVE-2023-30198EPSS 6% Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php. Winbizpayment after 1.0.2 Fix from $1,9502023-06-12 HIGH 7.2 CVE-2023-3172 Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20. Froxlor 2.0.20+ Fix from $1,9502023-06-09 HIGH 8.8 CVE-2023-34096EPSS 63% Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, … Thruk 3.06.2+ Fix from $1,9502023-06-08 MEDIUM 5.3 CVE-2023-34238 Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vul… Gatsby 4.25.7 / 5.9.1+ Fix from $1,6002023-06-08 HIGH 7.5 CVE-2023-1864 FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to a path traversal, which could allow an attacker to remotely read files on … Roboguide Handlingpro Firmware 9_rev.zd+ Fix from $1,9502023-06-07 HIGH 7.5 CVE-2023-33510 Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters. Jeecg P3 Biz Chat No fix yet Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2020-36728 The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows un… Adning Advertising 1.5.6+ Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2023-34409 In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sani… Monitoring And Management 2.37.1+ Fix from $2,3002023-06-06 HIGH 7.8 CVE-2023-33747 CloudPanel v2.2.2 allows attackers to execute a path traversal. Cloudpanel after 2.2.2 Fix from $1,9502023-06-06 MEDIUM 5.3 CVE-2023-33524 Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumerates Contact information on t… Tamale Rms 23.1+ Fix from $1,6002023-06-05 MEDIUM 6.5 CVE-2023-33690 SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a b… Sonicjs after 0.7.0 Fix from $1,6002023-06-05 HIGH 7.8 CVE-2023-3098 A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The … Youker Assistant 3.0.2-0kylin6k70-23+ Fix from $1,9502023-06-05 HIGH 7.5 CVE-2023-34407 OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL. Office Player No fix yet Fix from $1,9502023-06-05 MEDIUM 6.5 CVE-2023-28163 When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resol… Firefox 102.9 / 111.0+ Fix from $1,6002023-06-02 HIGH 7.5 CVE-2023-27639 An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the P… Custom Product Designer after 2.1.4 Fix from $1,9502023-06-01 HIGH 7.5 CVE-2023-27640 An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the P… Custom Product Designer after 2.1.4 Fix from $1,9502023-06-01 CRITICAL 9.8 CVE-2023-29736 Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in i… Keyboard Themes No fix yet Fix from $2,3002023-06-01 HIGH 8.1 CVE-2023-32714EPSS 43% In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path trave… Splunk 4.0.1 / 8.1.14+ Fix from $1,9502023-06-01 MEDIUM 5.5 CVE-2023-33544 hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompressi… Hawtio No fix yet Fix from $1,6002023-06-01 HIGH 7.5 CVE-2023-29159 Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files i… Starlette 0.27.0+ Fix from $1,9502023-06-01 CRITICAL 10.0 CVE-2023-2909 EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Aff… Adm after 4.2.1.rge2 Fix from $2,3002023-05-31 HIGH 7.2 CVE-2023-2435 The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This a… Blog In Blog after 1.1.1 Fix from $1,9502023-05-31 HIGH 7.5 CVE-2023-30197 Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal informat… Myinventory 1.6.7+ Fix from $1,9502023-05-31 CRITICAL 9.8 CVE-2022-47526 Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker c… Fox Datadiode Firmware Mitigation only Fix from $2,3002023-05-31 HIGH 7.1 CVE-2023-28344 An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view c… Insight No fix yet Fix from $1,9502023-05-31 HIGH 8.8 CVE-2023-33177EPSS 7% Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded… Xibo 2.3.17 / 3.3.5+ Fix from $1,9502023-05-30