Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-22
Total 5025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10553 1 Nagios 1 Nagios Xi 2018-06-07 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.
CVE-2017-18263 1 Seagate 2 Personal Cloud, Personal Cloud Firmware 2018-06-05 5.0 MEDIUM 7.5 HIGH
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
CVE-2018-9921 1 Cmsmadesimple 1 Cms Made Simple 2018-05-25 5.0 MEDIUM 5.3 MEDIUM
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
CVE-2017-1723 1 Ibm 3 Qradar Incident Forensics, Qradar Network Insights, Qradar Security Information And Event Manager 2018-05-25 4.0 MEDIUM 6.5 MEDIUM
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 134812.
CVE-2018-1000161 1 Nmap 1 Nmap 2018-05-24 3.5 LOW 5.7 MEDIUM
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.
CVE-2018-7539 1 Appeartv 4 Xc5000, Xc5000 Firmware, Xc5100 and 1 more 2018-05-23 7.8 HIGH 9.8 CRITICAL
On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can lead to full compromise of the device.
CVE-2018-10122 1 Chanzhi 1 Chanzhi 2018-05-23 5.0 MEDIUM 7.5 HIGH
QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) pro1.6 allows remote attackers to read arbitrary files via directory traversal sequences in the pathname parameter to www/file.php.
CVE-2018-9118 1 99robots 1 Wp Background Takeover Advertisements 2018-05-22 5.0 MEDIUM 7.5 HIGH
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
CVE-2018-10176 1 Digitalguardian 1 Management Console 2018-05-22 4.0 MEDIUM 6.5 MEDIUM
Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
CVE-2014-2069 1 Eshtery.she7ata 1 Eshtery Cms 2018-05-21 5.0 MEDIUM 7.5 HIGH
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.
CVE-2018-9205 1 Drupal 1 Avatar Uploader 2018-05-21 5.0 MEDIUM 7.5 HIGH
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
CVE-2015-8235 1 Call-cc 1 Spiffy 2018-05-18 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in Spiffy before 5.4.
CVE-2018-9851 1 Gxlcms 1 Gxlcms Qy 2018-05-17 5.0 MEDIUM 7.5 HIGH
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of '|' instead of '/' as a directory separator, in conjunction with a ".." sequence.
CVE-2017-3163 1 Apache 1 Solr 2018-05-16 5.0 MEDIUM 7.5 HIGH
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
CVE-2018-10201 1 Ncomputing 1 Vspace Pro 2018-05-15 5.0 MEDIUM 7.5 HIGH
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.
CVE-2018-9850 1 Gxlcms 1 Gxlcms Qy 2018-05-14 6.4 MEDIUM 7.5 HIGH
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.
CVE-2016-8205 1 Brocade 1 Network Advisor 2018-05-09 10.0 HIGH 9.8 CRITICAL
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
CVE-2016-8206 1 Brocade 1 Network Advisor 2018-05-09 6.4 MEDIUM 7.5 HIGH
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.
CVE-2016-8207 1 Brocade 1 Network Advisor 2018-05-09 5.0 MEDIUM 7.5 HIGH
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.
CVE-2018-8909 1 Wire 1 Wire 2018-04-20 5.0 MEDIUM 7.5 HIGH
The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.