Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.5 CVE-2017-20181 A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the fi… Vocable Trainer 1.3.1+ Fix from $1,6002023-03-07 HIGH 7.8 CVE-2023-25304 An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file. Prism Launcher after 6.1 Fix from $1,9502023-03-06 HIGH 7.2 CVE-2023-1191 A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/TemplateController.java of the co… Fastcms No fix yet Fix from $1,9502023-03-06 HIGH 7.5 CVE-2023-26111 All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper … \@nubosoftware\/node Static No fix yet Fix from $1,9502023-03-06 CRITICAL 9.8 CVE-2023-22336 Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a … Rakuraku Pc Cloud Agent after 13.0.0.40 Fix from $2,3002023-03-06 MEDIUM 6.5 CVE-2023-1163 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul… Vigor 2960 Firmware No fix yet Fix from $1,6002023-03-03 HIGH 7.5 CVE-2020-5001 IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a s… Financial Transaction Manager after 3.2.7 Fix from $1,9502023-03-01 MEDIUM 6.5 CVE-2022-3162 Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g… Kubernetes after 1.25.3 Fix from $1,6002023-03-01 CRITICAL 9.8 CVE-2023-1112 A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is … Drag And Drop Multiple File Upload Contact Form 7 5.0.6.3+ Fix from $2,3002023-03-01 MEDIUM 6.5 CVE-2023-22772 An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability res… Sd Wan after 10.3.1.0 Fix from $1,6002023-03-01 MEDIUM 6.5 CVE-2023-22773 Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in … Arubaos after 10.3.1.0 Fix from $1,6002023-03-01 MEDIUM 6.5 CVE-2023-22774 Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in … Arubaos after 10.3.1.0 Fix from $1,6002023-03-01 HIGH 7.5 CVE-2022-41722 A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "… Go 1.19.6+ Fix from $1,9502023-02-28 CRITICAL 9.8 CVE-2023-0339 Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Managem… Web Policy Agents after 5.10.1 Fix from $2,3002023-02-28 CRITICAL 9.8 CVE-2023-0511 Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Manage… Java Policy Agents after 5.10.1 Fix from $2,3002023-02-28 HIGH 7.8 CVE-2023-20943 In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could … Android Patch available Fix from $1,9502023-02-28 HIGH 7.5 CVE-2023-25265 Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system. Tornado 2.9.5+ Fix from $1,9502023-02-28 HIGH 7.5 CVE-2023-26255EPSS 47% An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying … Stagil Navigation 2.0.52+ Fix from $1,9502023-02-28 HIGH 7.5 CVE-2023-26256EPSS 12% An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying … Stagil Navigation 2.0.52+ Fix from $1,9502023-02-28 HIGH 7.5 CVE-2023-26758 Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService. Erp No fix yet Fix from $1,9502023-02-27 HIGH 8.8 CVE-2023-1044 A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file… Muyucms No fix yet Fix from $1,9502023-02-26 HIGH 8.1 CVE-2023-1045 A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.p… Muyucms No fix yet Fix from $1,9502023-02-26 HIGH 8.8 CVE-2022-48362EPSS 9% Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A r… Manageengine Desktop Central 10.1.2137.2+ Fix from $1,9502023-02-25 MEDIUM 5.5 CVE-2023-1009EPSS 16% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function… Vigor2960 Firmware No fix yet Fix from $1,6002023-02-24 MEDIUM 6.5 CVE-2023-1002 A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown processing of the file index.php… Muyucms No fix yet Fix from $1,6002023-02-24 HIGH 7.8 CVE-2023-0104EPSS 22% The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an … Easybuilder Pro 6.07.02.480 / 6.08.01.350+ Fix from $1,9502023-02-22 HIGH 8.8 CVE-2023-22973 A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via th… Openemr 7.0.0+ Fix from $1,9502023-02-22 HIGH 7.5 CVE-2023-25579 Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and norm… Nextcloud Server 20.0.14 / 21.0.9+ Fix from $1,9502023-02-22 MEDIUM 6.5 CVE-2022-41216 Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system. Cloudflow 2.3.2+ Fix from $1,6002023-02-22 HIGH 7.5 CVE-2023-23063 Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi. Nvt Web Server No fix yet Fix from $1,9502023-02-22