Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-30380
An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.
Dedecms
No fix yet
MEDIUM 6.5
CVE-2023-2336
Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.
Pimcore
10.5.21+
HIGH 8.8
CVE-2023-24836
SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can …
Ehrd Ctms
Mitigation only
HIGH 7.8
CVE-2023-26243
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt …
Gen5w L Firmware
No fix yet
MEDIUM 6.5
CVE-2023-30265
CLTPHP <=6.0 is vulnerable to Directory Traversal.
Cltphp
after 6.0
HIGH 7.5
CVE-2023-2273
Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI arg…
Insight Agent
3.3.0+
HIGH 7.5
CVE-2023-25652EPSS 52%
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by fe…
Git
2.30.9 / 2.31.8+
MEDIUM 6.5
CVE-2023-23838
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
Database Performance Analyzer
2023.2+
MEDIUM 6.5
CVE-2023-29200
Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in …
Contao
4.9.40 / 4.13.21+
CRITICAL 9.8
CVE-2023-27105
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music …
Eddict Player
No fix yet
HIGH 8.1
CVE-2023-30626
Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid…
Jellyfin
10.8.10+
HIGH 7.2
CVE-2023-22914
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series fi…
Usg Flex 100 Firmware
after 5.35
HIGH 7.5
CVE-2022-48476
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
Ktor
2.3.0+
HIGH 7.5
CVE-2023-31059EPSS 6%
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.
Repetier Server
after 1.4.10
HIGH 7.8
CVE-2023-25508
NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download …
Bmc
3.39.30+
HIGH 7.5
CVE-2023-30620
mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction is being performed using `tar…
Mindsdb
after 23.1.5.0
HIGH 7.5
CVE-2023-26101
In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vuln…
Flowmon Packet Investigator
12.1.0+
MEDIUM 6.5
CVE-2023-28459EPSS 7%
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigge…
Pretalx
after 2.3.1
HIGH 7.8
CVE-2023-21093
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traver…
Android
Patch available
HIGH 7.5
CVE-2023-29887
A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File paramet…
Spreadsheet Reader
No fix yet
MEDIUM 6.5
CVE-2023-29004
hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerability was found in the current…
Roxy Wi
after 6.3.9.0
HIGH 8.8
CVE-2023-1109
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughou…
Energy Axc Pu
after 04.15.00.00
HIGH 7.5
CVE-2022-34126
The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.
Activity
3.1.1+
HIGH 7.5
CVE-2022-34127EPSS 7%
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.
Manageentities
4.0.2+
HIGH 7.5
CVE-2022-47501EPSS 10%
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a
pre-authentication attack.
Thi…
Ofbiz
18.12.07+
MEDIUM 5.3
CVE-2023-26559
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015…
Oxygen Content Fusion
5.0.3 / 23.1.1.4+
CRITICAL 9.8
CVE-2022-47027
Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary travers…
Fast Typing Keyboard
No fix yet
CRITICAL 9.8
CVE-2023-27648
Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via t…
Change Color Of Keypad
No fix yet
HIGH 7.5
CVE-2023-26969
Atropim 1.5.26 is vulnerable to Directory Traversal.
Atropim
No fix yet
CRITICAL 9.1
CVE-2023-27812
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
Bloofoxcms
Mitigation only