Total
5025 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-14322 | 2 Microsoft, Palletsprojects | 2 Windows, Werkzeug | 2023-01-31 | 5.0 MEDIUM | 7.5 HIGH |
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. | |||||
CVE-2020-14946 | 1 Globalradar | 1 Bsa Radar | 2023-01-30 | 4.0 MEDIUM | 4.3 MEDIUM |
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files. | |||||
CVE-2023-23314 | 1 Zdir Project | 1 Zdir | 2023-01-30 | N/A | 8.8 HIGH |
An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file. | |||||
CVE-2021-3762 | 1 Redhat | 2 Clair, Quay | 2023-01-30 | 7.5 HIGH | 9.8 CRITICAL |
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution. | |||||
CVE-2019-11822 | 1 Synology | 1 Photo Station | 2023-01-30 | 4.0 MEDIUM | 6.5 MEDIUM |
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter. | |||||
CVE-2022-43975 | 1 Ge | 2 Ms 3000, Ms 3000 Firmware | 2023-01-30 | N/A | 7.5 HIGH |
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888. | |||||
CVE-2022-46959 | 1 Sonic Project | 1 Sonic | 2023-01-30 | N/A | 4.3 MEDIUM |
An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal. | |||||
CVE-2019-11826 | 1 Synology | 1 Moments | 2023-01-30 | 6.5 MEDIUM | 8.8 HIGH |
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter. | |||||
CVE-2018-20470 | 1 Sahipro | 1 Sahi Pro | 2023-01-30 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files. | |||||
CVE-2018-3725 | 1 Hekto Project | 1 Hekto | 2023-01-30 | 5.0 MEDIUM | 7.5 HIGH |
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3731 | 1 Public.js Project | 1 Public.js | 2023-01-30 | 5.0 MEDIUM | 7.5 HIGH |
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path. | |||||
CVE-2019-4384 | 1 Ibm | 1 Campaign | 2023-01-30 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172. | |||||
CVE-2018-3730 | 1 Mcstatic Project | 1 Mcstatic | 2023-01-30 | 5.0 MEDIUM | 7.5 HIGH |
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3744 | 1 Html-pages Project | 1 Html-pages | 2023-01-30 | 5.0 MEDIUM | 9.8 CRITICAL |
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL. | |||||
CVE-2018-3715 | 1 Glance Project | 1 Glance | 2023-01-30 | 4.0 MEDIUM | 6.5 MEDIUM |
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3734 | 1 Stattic Project | 1 Stattic | 2023-01-30 | 5.0 MEDIUM | 7.5 HIGH |
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path. | |||||
CVE-2023-0290 | 1 Rapid7 | 1 Velociraptor | 2023-01-30 | N/A | 4.3 MEDIUM |
Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory traversal in where the collection task could be written. It was possible to provide a client id of "../clients/server" to schedule the collection for the server (as a server artifact), but only require privileges to schedule collections on the client. Normally, to schedule an artifact on the server, the COLLECT_SERVER permission is required. This permission is normally only granted to "administrator" role. Due to this issue, it is sufficient to have the COLLECT_CLIENT privilege, which is normally granted to the "investigator" role. To exploit this vulnerability, the attacker must already have a Velociraptor user account at least "investigator" level, and be able to authenticate to the GUI and issue an API call to the backend. Typically, most users deploy Velociraptor with limited access to a trusted group, and most users will already be administrators within the GUI. This issue affects Velociraptor versions before 0.6.7-5. Version 0.6.7-5, released January 16, 2023, fixes the issue. | |||||
CVE-2020-15050 | 1 Supremainc | 1 Biostar 2 | 2023-01-27 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal. | |||||
CVE-2018-6677 | 1 Mcafee | 1 Mcafee Web Gateway | 2023-01-27 | 9.0 HIGH | 9.1 CRITICAL |
Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to gain elevated privileges via unspecified vectors. | |||||
CVE-2020-14461 | 1 Zyxel | 2 Wap6806, Wap6806 Firmware | 2023-01-27 | 5.0 MEDIUM | 8.6 HIGH |
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. |