Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-3241
A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/…
Otcms
after 6.62
CRITICAL 9.8
CVE-2023-2278
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' f…
Wp Directory Kit
1.2.0+
CRITICAL 9.1
CVE-2023-34342
AMI BMC contains a vulnerability in the IPMI handler, where an
attacker can upload and download arbitrary files under certain circumstances,
which ma…
Megarac Sp X
12.7 / 13.5+
MEDIUM 6.5
CVE-2023-34345
AMI BMC contains a vulnerability in the SPX REST API, where an
attacker with the required privileges can access arbitrary files, which may
lead to in…
Megarac Sp X
12.7 / 13.5+
HIGH 7.5
CVE-2023-30198EPSS 6%
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.
Winbizpayment
after 1.0.2
HIGH 7.2
CVE-2023-3172
Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
Froxlor
2.0.20+
HIGH 8.8
CVE-2023-34096EPSS 63%
Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, …
Thruk
3.06.2+
MEDIUM 5.3
CVE-2023-34238
Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vul…
Gatsby
4.25.7 / 5.9.1+
HIGH 7.5
CVE-2023-1864
FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to
a path traversal, which could allow an attacker to remotely read files
on …
Roboguide Handlingpro Firmware
9_rev.zd+
HIGH 7.5
CVE-2023-33510
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
Jeecg P3 Biz Chat
No fix yet
CRITICAL 9.8
CVE-2020-36728
The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows un…
Adning Advertising
1.5.6+
CRITICAL 9.8
CVE-2023-34409
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sani…
Monitoring And Management
2.37.1+
HIGH 7.8
CVE-2023-33747
CloudPanel v2.2.2 allows attackers to execute a path traversal.
Cloudpanel
after 2.2.2
MEDIUM 5.3
CVE-2023-33524
Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumerates Contact information on t…
Tamale Rms
23.1+
MEDIUM 6.5
CVE-2023-33690
SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a b…
Sonicjs
after 0.7.0
HIGH 7.8
CVE-2023-3098
A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The …
Youker Assistant
3.0.2-0kylin6k70-23+
HIGH 7.5
CVE-2023-34407
OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.
Office Player
No fix yet
MEDIUM 6.5
CVE-2023-28163
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resol…
Firefox
102.9 / 111.0+
HIGH 7.5
CVE-2023-27639
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the P…
Custom Product Designer
after 2.1.4
HIGH 7.5
CVE-2023-27640
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the P…
Custom Product Designer
after 2.1.4
CRITICAL 9.8
CVE-2023-29736
Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in i…
Keyboard Themes
No fix yet
HIGH 8.1
CVE-2023-32714EPSS 43%
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path trave…
Splunk
4.0.1 / 8.1.14+
MEDIUM 5.5
CVE-2023-33544
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompressi…
Hawtio
No fix yet
HIGH 7.5
CVE-2023-29159
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files i…
Starlette
0.27.0+
CRITICAL 10.0
CVE-2023-2909
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Aff…
Adm
after 4.2.1.rge2
HIGH 7.2
CVE-2023-2435
The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This a…
Blog In Blog
after 1.1.1
HIGH 7.5
CVE-2023-30197
Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal informat…
Myinventory
1.6.7+
CRITICAL 9.8
CVE-2022-47526
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker c…
Fox Datadiode Firmware
Mitigation only
HIGH 7.1
CVE-2023-28344
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view c…
Insight
No fix yet
HIGH 8.8
CVE-2023-33177EPSS 7%
Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded…
Xibo
2.3.17 / 3.3.5+