Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2023-30380 An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal. Dedecms No fix yet Fix from $1,9502023-04-27 MEDIUM 6.5 CVE-2023-2336 Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21. Pimcore 10.5.21+ Fix from $1,6002023-04-27 HIGH 8.8 CVE-2023-24836 SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can … Ehrd Ctms Mitigation only Fix from $1,9502023-04-27 HIGH 7.8 CVE-2023-26243 An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt … Gen5w L Firmware No fix yet Fix from $1,9502023-04-27 MEDIUM 6.5 CVE-2023-30265 CLTPHP <=6.0 is vulnerable to Directory Traversal. Cltphp after 6.0 Fix from $1,6002023-04-26 HIGH 7.5 CVE-2023-2273 Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI arg… Insight Agent 3.3.0+ Fix from $1,9502023-04-26 HIGH 7.5 CVE-2023-25652EPSS 52% Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by fe… Git 2.30.9 / 2.31.8+ Fix from $1,9502023-04-25 MEDIUM 6.5 CVE-2023-23838 Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. Database Performance Analyzer 2023.2+ Fix from $1,6002023-04-25 MEDIUM 6.5 CVE-2023-29200 Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in … Contao 4.9.40 / 4.13.21+ Fix from $1,6002023-04-25 CRITICAL 9.8 CVE-2023-27105 A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music … Eddict Player No fix yet Fix from $2,3002023-04-25 HIGH 8.1 CVE-2023-30626 Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid… Jellyfin 10.8.10+ Fix from $1,9502023-04-24 HIGH 7.2 CVE-2023-22914 A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series fi… Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 HIGH 7.5 CVE-2022-48476 In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible Ktor 2.3.0+ Fix from $1,9502023-04-24 HIGH 7.5 CVE-2023-31059EPSS 6% Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php. Repetier Server after 1.4.10 Fix from $1,9502023-04-24 HIGH 7.8 CVE-2023-25508 NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download … Bmc 3.39.30+ Fix from $1,9502023-04-22 HIGH 7.5 CVE-2023-30620 mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction is being performed using `tar… Mindsdb after 23.1.5.0 Fix from $1,9502023-04-21 HIGH 7.5 CVE-2023-26101 In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vuln… Flowmon Packet Investigator 12.1.0+ Fix from $1,9502023-04-21 MEDIUM 6.5 CVE-2023-28459EPSS 7% pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigge… Pretalx after 2.3.1 Fix from $1,6002023-04-20 HIGH 7.8 CVE-2023-21093 In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traver… Android Patch available Fix from $1,9502023-04-19 HIGH 7.5 CVE-2023-29887 A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File paramet… Spreadsheet Reader No fix yet Fix from $1,9502023-04-18 MEDIUM 6.5 CVE-2023-29004 hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerability was found in the current… Roxy Wi after 6.3.9.0 Fix from $1,6002023-04-17 HIGH 8.8 CVE-2023-1109 In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughou… Energy Axc Pu after 04.15.00.00 Fix from $1,9502023-04-17 HIGH 7.5 CVE-2022-34126 The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter. Activity 3.1.1+ Fix from $1,9502023-04-16 HIGH 7.5 CVE-2022-34127EPSS 7% The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter. Manageentities 4.0.2+ Fix from $1,9502023-04-16 HIGH 7.5 CVE-2022-47501EPSS 10% Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. Thi… Ofbiz 18.12.07+ Fix from $1,9502023-04-14 MEDIUM 5.3 CVE-2023-26559 A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015… Oxygen Content Fusion 5.0.3 / 23.1.1.4+ Fix from $1,6002023-04-14 CRITICAL 9.8 CVE-2022-47027 Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary travers… Fast Typing Keyboard No fix yet Fix from $2,3002023-04-14 CRITICAL 9.8 CVE-2023-27648 Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via t… Change Color Of Keypad No fix yet Fix from $2,3002023-04-14 HIGH 7.5 CVE-2023-26969 Atropim 1.5.26 is vulnerable to Directory Traversal. Atropim No fix yet Fix from $1,9502023-04-14 CRITICAL 9.1 CVE-2023-27812 bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. Bloofoxcms Mitigation only Fix from $2,3002023-04-13