Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2017-20181
A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the fi…
Vocable Trainer
1.3.1+
HIGH 7.8
CVE-2023-25304
An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file.
Prism Launcher
after 6.1
HIGH 7.2
CVE-2023-1191
A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/TemplateController.java of the co…
Fastcms
No fix yet
HIGH 7.5
CVE-2023-26111
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper …
\@nubosoftware\/node Static
No fix yet
CRITICAL 9.8
CVE-2023-22336
Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a …
Rakuraku Pc Cloud Agent
after 13.0.0.40
MEDIUM 6.5
CVE-2023-1163
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul…
Vigor 2960 Firmware
No fix yet
HIGH 7.5
CVE-2020-5001
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a s…
Financial Transaction Manager
after 3.2.7
MEDIUM 6.5
CVE-2022-3162
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g…
Kubernetes
after 1.25.3
CRITICAL 9.8
CVE-2023-1112
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is …
Drag And Drop Multiple File Upload Contact Form 7
5.0.6.3+
MEDIUM 6.5
CVE-2023-22772
An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability res…
Sd Wan
after 10.3.1.0
MEDIUM 6.5
CVE-2023-22773
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in …
Arubaos
after 10.3.1.0
MEDIUM 6.5
CVE-2023-22774
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in …
Arubaos
after 10.3.1.0
HIGH 7.5
CVE-2022-41722
A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "…
Go
1.19.6+
CRITICAL 9.8
CVE-2023-0339
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Managem…
Web Policy Agents
after 5.10.1
CRITICAL 9.8
CVE-2023-0511
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Manage…
Java Policy Agents
after 5.10.1
HIGH 7.8
CVE-2023-20943
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could …
Android
Patch available
HIGH 7.5
CVE-2023-25265
Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system.
Tornado
2.9.5+
HIGH 7.5
CVE-2023-26255EPSS 47%
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying …
Stagil Navigation
2.0.52+
HIGH 7.5
CVE-2023-26256EPSS 12%
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying …
Stagil Navigation
2.0.52+
HIGH 7.5
CVE-2023-26758
Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.
Erp
No fix yet
HIGH 8.8
CVE-2023-1044
A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file…
Muyucms
No fix yet
HIGH 8.1
CVE-2023-1045
A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.p…
Muyucms
No fix yet
HIGH 8.8
CVE-2022-48362EPSS 9%
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A r…
Manageengine Desktop Central
10.1.2137.2+
MEDIUM 5.5
CVE-2023-1009EPSS 16%
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function…
Vigor2960 Firmware
No fix yet
MEDIUM 6.5
CVE-2023-1002
A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown processing of the file index.php…
Muyucms
No fix yet
HIGH 7.8
CVE-2023-0104EPSS 22%
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an …
Easybuilder Pro
6.07.02.480 / 6.08.01.350+
HIGH 8.8
CVE-2023-22973
A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via th…
Openemr
7.0.0+
HIGH 7.5
CVE-2023-25579
Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and norm…
Nextcloud Server
20.0.14 / 21.0.9+
MEDIUM 6.5
CVE-2022-41216
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.
Cloudflow
2.3.2+
HIGH 7.5
CVE-2023-23063
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
Nvt Web Server
No fix yet