Total
8266 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-44172 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
|
|||||
| CVE-2023-44171 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
|
|||||
| CVE-2023-44170 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
|
|||||
| CVE-2023-44169 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
|
|||||
| CVE-2023-43825 | 1 Ekakin | 1 Shihonkanri Plus | 2024-11-21 | N/A | 7.8 HIGH |
|
Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arbitrary code by having a legitimate user import a specially crafted backup file of the product..
|
|||||
| CVE-2023-43803 | 1 Arduino | 1 Create Agent | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP POST request. This issue has been addressed in version `1.3.3`. ...
Show More |
|||||
| CVE-2023-43802 | 1 Arduino | 1 Create Agent | 2024-11-21 | N/A | 7.1 HIGH |
|
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can escalate their privileges to those of the user running the Arduino Create Agent service via a crafted HTTP POST request. This issue has been addressed in version `1.3.3`. Users are advised to upgrad ...
Show More |
|||||
| CVE-2023-43801 | 1 Arduino | 1 Create Agent | 2024-11-21 | N/A | 6.1 MEDIUM |
|
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP DELETE request. This issue has been addressed in version `1.3.3` ...
Show More |
|||||
| CVE-2023-43662 | 1 Shokoanime | 1 Shokoserver | 2024-11-21 | N/A | 8.6 HIGH |
|
ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read. This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the ...
Show More |
|||||
| CVE-2023-43648 | 1 Basercms | 1 Basercms | 2024-11-21 | N/A | 4.9 MEDIUM |
|
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
|
|||||
| CVE-2023-43627 | 1 Furunosystems | 4 Acera 1310, Acera 1310 Firmware, Acera 1320 and 1 more | 2024-11-21 | N/A | 5.7 MEDIUM |
|
Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter critical information such as system files by sending a specially crafted request. They are affected when running in ST(Standalone) mode.
|
|||||
| CVE-2023-43616 | 1 Schollz | 1 Croc | 2024-11-21 | N/A | 5.5 MEDIUM |
|
An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.
|
|||||
| CVE-2023-43586 | 1 Zoom | 4 Meeting Software Development Kit, Video Software Development Kit, Virtual Desktop Infrastructure and 1 more | 2024-11-21 | N/A | 7.3 HIGH |
|
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
|
|||||
| CVE-2023-43382 | 1 Iteachyou | 1 Dreamer Cms | 2024-11-21 | N/A | 8.8 HIGH |
|
Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the themePath in the uploaded template function.
|
|||||
| CVE-2023-43256 | 1 Gladysassistant | 1 Gladys Assistant | 2024-11-21 | N/A | 6.5 MEDIUM |
|
A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
|
|||||
| CVE-2023-43216 | 1 Seacms | 1 Seacms | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
|
|||||
| CVE-2023-43121 | 1 Extremenetworks | 1 Exos | 2024-11-21 | N/A | 7.5 HIGH |
|
A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.
|
|||||
| CVE-2023-43070 | 1 Dell | 1 Smartfabric Storage Software | 2024-11-21 | N/A | 6.3 MEDIUM |
|
Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A remote authenticated attacker could potentially exploit this vulnerability, leading to modify or write arbitrary files to arbitrary locations in the license container.
|
|||||
| CVE-2023-43044 | 1 Ibm | 1 License Metric Tool | 2024-11-21 | N/A | 5.3 MEDIUM |
|
IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 266893.
|
|||||
| CVE-2023-42819 | 1 Fit2cloud | 1 Jumpserver | 2024-11-21 | N/A | 8.9 HIGH |
|
JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Template' menu and create a playbook named 'test'. Get the playbook id from the detail page, like 'e0adabef-c38f-492d-bd92-832bacc3df5f'. An attacker can exploit the directory traversal flaw using the provided URL to access and retrieve the contents of the file. `https://jumpserver-ip/api/v1/ops/playbook/e0adabef-c38f-492d-bd92-832bacc3df5f/file/?key=.. ...
Show More |
|||||
| CVE-2023-42804 | 1 Bigbluebutton | 1 Bigbluebutton | 2024-11-21 | N/A | 3.1 LOW |
|
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain extensions (txt, swf, svg, png). In version 2.6.0-beta.1, input validation was added on the parameters being passed and dangerous characters are stripped. There are no known workarounds.
|
|||||
| CVE-2023-42796 | 1 Siemens | 4 Cp-8031, Cp-8031 Firmware, Cp-8050 and 1 more | 2024-11-21 | N/A | 7.5 HIGH |
|
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11). The web server of affected devices fails to properly sanitize user input for the /sicweb-ajax/tmproot/ endpoint.
This could allow an authenticated remote attacker to traverse directories on the system and download arbitrary files. By exploring active session IDs, the vulnerability could potentially be leveraged to escalate privileges to the adminis ...
Show More |
|||||
| CVE-2023-42657 | 1 Progress | 1 Ws Ftp Server | 2024-11-21 | N/A | 9.9 CRITICAL |
|
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system.
|
|||||
| CVE-2023-42488 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | N/A | 7.5 HIGH |
|
EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
|
|||||
| CVE-2023-42487 | 1 Soundminer | 1 Soundminer | 2024-11-21 | N/A | 7.5 HIGH |
|
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
|
|||||
| CVE-2023-42462 | 1 Glpi-project | 1 Glpi | 2024-11-21 | N/A | 7.7 HIGH |
|
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
|
|||||
| CVE-2023-42456 | 1 Memorysafety | 1 Sudo | 2024-11-21 | N/A | 3.1 LOW |
|
Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requiring authentication every once in a while in every terminal or process group. Only once a configurable timeout has passed will the user have to re-authenticate themselves. Supporting this functionality is a set of session files (timestamps) for each user, stored in `/var/run/sudo-rs/ts`. These files are named according to the username from which the ...
Show More |
|||||
| CVE-2023-42428 | 1 Cubecart | 1 Cubecart | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.
|
|||||
| CVE-2023-42280 | 1 Springernature | 1 Mee-admin | 2024-11-21 | N/A | 7.5 HIGH |
|
mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not verify the incoming data, resulting in arbitrary file reading.
|
|||||
| CVE-2023-42000 | 1 Arcserve | 1 Udp | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.
|
|||||
| CVE-2023-41930 | 1 Jenkins | 1 Job Configuration History | 2024-11-21 | N/A | 4.3 MEDIUM |
|
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
|
|||||
| CVE-2023-41888 | 1 Glpi-project | 1 Glpi | 2024-11-21 | N/A | 5.3 MEDIUM |
|
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The lack of path filtering on the GLPI URL may allow an attacker to transmit a malicious URL of login page that can be used to attempt a phishing attack on user credentials. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
|
|||||
| CVE-2023-41825 | 2024-11-21 | N/A | 2.8 LOW | ||
|
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.
|
|||||
| CVE-2023-41599 | 1 Jfinalcms Project | 1 Jfinalcms | 2024-11-21 | N/A | 5.3 MEDIUM |
|
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
|
|||||
| CVE-2023-41578 | 1 Jeecg | 1 Jeecg Boot | 2024-11-21 | N/A | 7.5 HIGH |
|
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
|
|||||
| CVE-2023-41373 | 1 F5 | 18 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 15 more | 2024-11-21 | N/A | 9.9 CRITICAL |
|
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
|
|||||
| CVE-2023-41356 | 1 Wisdomgarden | 1 Tronclass Ilearn | 2024-11-21 | N/A | 6.5 MEDIUM |
|
NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.
|
|||||
| CVE-2023-41344 | 1 Ncsist | 1 Mobile Device Manager | 2024-11-21 | N/A | 7.5 HIGH |
|
NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.
|
|||||
| CVE-2023-41302 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | N/A | 7.5 HIGH |
|
Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally.
|
|||||
| CVE-2023-41057 | 1 Plannigan | 1 Hyper Bump It | 2024-11-21 | N/A | 5.5 MEDIUM |
|
hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern from the configuration file. That is combined with the project root directory to construct a full glob pattern that is used to find files that should be edited. These matched files should be contained within the project root directory, but that is not checked. This could result in changes being written to files outside of the project. The default behaviour of `hyper-bump-it` i ...
Show More |
|||||