Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.8 CVE-2022-42470 A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an at… Forticlient 7.0.8+ Fix from $1,9502023-04-11 HIGH 7.3 CVE-2023-26293 A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TI… Tia Portal Patch available Fix from $1,9502023-04-11 MEDIUM 6.5 CVE-2023-29186EPSS 23% In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrit… Netweaver Mitigation only Fix from $1,6002023-04-11 CRITICAL 9.8 CVE-2023-1478 The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path t… Hummingbird 3.4.2+ Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-27603 In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead… Linkis after 1.3.1 Fix from $2,3002023-04-10 HIGH 8.8 CVE-2023-1956 A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown… Online Computer And Laptop Store No fix yet Fix from $1,9502023-04-08 CRITICAL 9.8 CVE-2023-29478 BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesys… Bibliocraft 2.4.6+ Fix from $2,3002023-04-07 HIGH 7.5 CVE-2023-26820 siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js. Siteproxy No fix yet Fix from $1,9502023-04-07 HIGH 7.5 CVE-2020-19678 Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive info… Pfsense Patch available Fix from $1,9502023-04-06 MEDIUM 6.5 CVE-2023-20129 Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) co… Prime Infrastructure 3.10.2 / 5.0.2.5+ Fix from $1,6002023-04-05 CRITICAL 9.8 CVE-2020-19279 Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links. Wide Mitigation only Fix from $2,3002023-04-04 HIGH 7.1 CVE-2023-25303 ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the instal… Atlauncher 3.4.27.0+ Fix from $1,9502023-04-04 HIGH 7.1 CVE-2023-25305 PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the inst… Polymc 5.0+ Fix from $1,9502023-04-04 MEDIUM 6.5 CVE-2022-43771EPSS 24% Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes … Vantara Pentaho Business Analytics Server 9.3.0.1+ Fix from $1,6002023-04-03 HIGH 8.8 CVE-2023-27534 A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix … Curl after 7.88.1 Fix from $1,9502023-03-30 HIGH 8.8 CVE-2022-23522 MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archive()` from a remotely retrieve… Mindsdb 22.11.4.3+ Fix from $1,9502023-03-30 HIGH 8.8 CVE-2023-28833 Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to … Nextcloud Server 23.0.14 / 24.0.10+ Fix from $1,9502023-03-30 HIGH 7.5 CVE-2023-28732 Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access… Acymailing 8.3.0+ Fix from $1,9502023-03-30 CRITICAL 9.8 CVE-2022-36981EPSS 83% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication… Avalanche 6.3.4+ Fix from $2,3002023-03-29 HIGH 7.5 CVE-2022-36982EPSS 74% This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication i… Avalanche 6.3.4+ Fix from $1,9502023-03-29 CRITICAL 9.1 CVE-2022-2560EPSS 78% This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authenticat… Completeftp Server 22.1.1+ Fix from $2,3002023-03-29 HIGH 8.1 CVE-2023-27700 MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html. Muyucms No fix yet Fix from $1,9502023-03-28 MEDIUM 5.3 CVE-2022-48361 The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in r… Emui No fix yet Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-0241EPSS 9% pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the… Pgadmin 4 6.19+ Fix from $1,6002023-03-27 CRITICAL 9.8 CVE-2023-1142 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and … Infrasuite Device Master 1.0.5+ Fix from $2,3002023-03-27 HIGH 8.8 CVE-2023-1134 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to r… Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 MEDIUM 6.5 CVE-2022-32199 db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file para… Scriptcase after 9.9.008 Fix from $1,6002023-03-27 CRITICAL 9.8 CVE-2023-26802EPSS 49% An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication… Dcbi Netlog Lab Firmware No fix yet Fix from $2,3002023-03-26 HIGH 7.5 CVE-2023-27055 Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request. Ptzapp 2 2.0.1051.53+ Fix from $1,9502023-03-24 CRITICAL 9.8 CVE-2023-1177EPSS 70% Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1. Mlflow 2.2.1+ Fix from $2,3002023-03-24