Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 6.5 CVE-2023-30509 Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of th… Edgeconnect Enterprise after 9.2.3.0 Fix from $1,6002023-05-16 MEDIUM 6.5 CVE-2023-30507 Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of th… Edgeconnect Enterprise after 9.2.3.0 Fix from $1,6002023-05-16 MEDIUM 6.5 CVE-2023-30508 Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of th… Edgeconnect Enterprise after 9.2.3.0 Fix from $1,6002023-05-16 CRITICAL 9.1 CVE-2023-31131 Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods… Greenplum Database 6.22.3+ Fix from $2,3002023-05-15 HIGH 7.5 CVE-2023-32309 PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when us… Pymdown Extensions 10.0+ Fix from $1,9502023-05-15 HIGH 8.1 CVE-2020-13377 The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to condu… Enterprise Va Max after 8.3.8 Fix from $1,9502023-05-12 MEDIUM 6.5 CVE-2023-23169 Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal. Pdfocus No fix yet Fix from $1,6002023-05-12 HIGH 7.5 CVE-2023-31477 A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directo… Gl S20 Firmware 3.216+ Fix from $1,9502023-05-11 MEDIUM 5.3 CVE-2023-29986 spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. Spring Boot Actuator Logview Mitigation only Fix from $1,6002023-05-11 HIGH 7.5 CVE-2023-30172 A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on t… Mlflow 2.0.1+ Fix from $1,9502023-05-11 MEDIUM 6.5 CVE-2023-27562 The n8n package 0.218.0 for Node.js allows Directory Traversal. N8n No fix yet Fix from $1,6002023-05-10 HIGH 7.8 CVE-2022-34855 Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of pri… Nuc Pro Software Suite 2.0.0.3+ Fix from $1,9502023-05-10 MEDIUM 5.3 CVE-2023-26126 All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the req… M.static after 2.2.0 Fix from $1,6002023-05-10 HIGH 7.5 CVE-2023-28127EPSS 59% A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure. Avalanche after 6.3.4.153 Fix from $1,9502023-05-09 MEDIUM 6.0 CVE-2023-20098 A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerabil… Catalyst Sd Wan Manager 20.9.1+ Fix from $1,6002023-05-09 HIGH 7.6 CVE-2023-29104 A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2… 6gk1411 1ac00 Firmware Patch available Fix from $1,9502023-05-09 HIGH 7.5 CVE-2023-31181 WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal Innokb Mitigation only Fix from $1,9502023-05-08 HIGH 7.5 CVE-2023-31179 AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the server, by an unspecified requ… Agilepoint Nx Mitigation only Fix from $1,9502023-05-08 HIGH 7.5 CVE-2023-30855 Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact … Pimcore 10.5.18+ Fix from $1,9502023-05-08 HIGH 7.5 CVE-2023-32235EPSS 39% Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traver… Ghost 5.42.1+ Fix from $1,9502023-05-05 HIGH 7.5 CVE-2023-25289EPSS 8% Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, all… Digital Reciptie No fix yet Fix from $1,9502023-05-04 CRITICAL 9.8 CVE-2023-30268 CLTPHP <=6.0 is vulnerable to Improper Input Validation. Cltphp after 6.0 Fix from $2,3002023-05-04 HIGH 7.5 CVE-2017-20184 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows … Powersoft after 2.1.1.1 Fix from $1,9502023-05-04 CRITICAL 9.8 CVE-2022-47757 In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the appli… Imo Mitigation only Fix from $2,3002023-05-04 HIGH 7.1 CVE-2023-27993 A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories f… Fortiadc 7.1.2+ Fix from $1,9502023-05-03 HIGH 8.8 CVE-2022-47875EPSS 10% A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code. Cloud No fix yet Fix from $1,9502023-05-02 HIGH 7.5 CVE-2022-48483 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download dir… 3cx 18.0.3.461+ Fix from $1,9502023-05-02 HIGH 7.5 CVE-2022-48482 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/downlo… 3cx 18.0.2.315+ Fix from $1,9502023-05-02 CRITICAL 9.8 CVE-2015-10105 A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This affects the function valid_js… Ip Blacklist Cloud after 3.42 Fix from $2,3002023-05-01 HIGH 7.5 CVE-2023-31483 tar/TarFileReader.cpp in Cauldron cbang before bastet-v8.1.17 has a directory traversal during extraction that allows the attacker to create or write… Cbang 8.1.17+ Fix from $1,9502023-04-28