Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-22
Total 5025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8463 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2021-07-21 5.0 MEDIUM 7.5 HIGH
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.
CVE-2020-26650 1 Atomx 1 Atomxcms 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
CVE-2019-9642 1 Pydio 1 Pydio 2021-07-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution via a proxy.php?hash=../../../../../var/lib/pydio/data/personal/guest/PoC.php request. This is related to plugins/action.share/src/Store/ShareStore.php.
CVE-2020-7648 1 Synk 1 Broker 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`
CVE-2020-9354 1 Smartclient 1 Smartclient 2021-07-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. path traversal.
CVE-2020-16136 1 Tgstation13 1 Tgstation-server 2021-07-21 6.8 MEDIUM 7.7 HIGH
In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory traversal ../ sequences in /Administration/Logs/ requests. The attacker is unable to enumerate files, however.
CVE-2020-15929 1 Ortussolutions 1 Testbox 2021-07-21 7.5 HIGH 9.8 CRITICAL
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
CVE-2020-7651 1 Synk 1 Broker 2021-07-21 4.0 MEDIUM 4.3 MEDIUM
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
CVE-2019-16902 1 Reputeinfosystems 1 Arforms 2021-07-21 6.4 MEDIUM 7.5 HIGH
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
CVE-2020-7650 1 Synk 1 Broker 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.
CVE-2019-16915 1 Netgate 1 Pfsense 2021-07-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.
CVE-2019-16246 1 Intesync 1 Solismed 2021-07-21 7.5 HIGH 9.8 CRITICAL
Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
CVE-2019-16867 1 Hongcms Project 1 Hongcms 2021-07-21 5.5 MEDIUM 6.5 MEDIUM
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)
CVE-2020-0520 1 Intel 1 Graphics Driver 2021-07-21 4.6 MEDIUM 7.8 HIGH
Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117 and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.
CVE-2020-12851 1 Pydio 1 Cells 2021-07-21 5.5 MEDIUM 8.1 HIGH
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted files will be placed in the targeted user folders.
CVE-2019-14424 1 Eq-3 3 Ccu2, Ccu2 Firmware, Cux-daemon 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
CVE-2020-9325 1 Aquaforest 1 Tiff Server 2021-07-21 5.0 MEDIUM 7.5 HIGH
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.
CVE-2020-7762 1 Jsreport 1 Jsreport-chrome-pdf 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
This affects the package jsreport-chrome-pdf before 1.10.0.
CVE-2020-29166 1 Rainbowfishsoftware 1 Pacsone Server 2021-07-21 5.0 MEDIUM 7.5 HIGH
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure.
CVE-2019-19459 1 Saltosystem 1 Proaccess Space 2021-07-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.