Total
8266 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-39407 | 1 Huawei | 1 Harmonyos | 2024-11-21 | N/A | 9.1 CRITICAL |
|
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
|
|||||
| CVE-2023-39402 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | N/A | 9.1 CRITICAL |
|
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
|
|||||
| CVE-2023-39401 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | N/A | 9.1 CRITICAL |
|
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
|
|||||
| CVE-2023-39400 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | N/A | 9.1 CRITICAL |
|
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
|
|||||
| CVE-2023-39299 | 1 Qnap | 1 Music Station | 2024-11-21 | N/A | 7.5 HIGH |
|
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following versions:
Music Station 4.8.11 and later
Music Station 5.1.16 and later
Music Station 5.3.23 and later
|
|||||
| CVE-2023-39163 | 2024-11-21 | N/A | 8.6 HIGH | ||
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Shop allows PHP Local File Inclusion.This issue affects Phlox Shop: from n/a through 2.0.0.
|
|||||
| CVE-2023-39141 | 1 Ziahamza | 1 Webui-aria2 | 2024-11-21 | N/A | 7.5 HIGH |
|
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
|
|||||
| CVE-2023-39139 | 1 Archive Project | 1 Archive | 2024-11-21 | N/A | 7.8 HIGH |
|
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
|
|||||
| CVE-2023-39138 | 1 Peakstep | 1 Zipfoundation | 2024-11-21 | N/A | 7.8 HIGH |
|
An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.
|
|||||
| CVE-2023-39135 | 1 Marmelroy | 1 Zip | 2024-11-21 | N/A | 7.8 HIGH |
|
An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.
|
|||||
| CVE-2023-39026 | 2 Filemage, Microsoft | 2 Filemage, Windows | 2024-11-21 | N/A | 7.5 HIGH |
|
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
|
|||||
| CVE-2023-38997 | 1 Opnsense | 1 Opnsense | 2024-11-21 | N/A | 7.2 HIGH |
|
A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.
|
|||||
| CVE-2023-38956 | 1 Zkteco | 1 Bioaccess Ivs | 2024-11-21 | N/A | 7.5 HIGH |
|
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
|
|||||
| CVE-2023-38879 | 1 Os4ed | 1 Opensis | 2024-11-21 | N/A | 7.5 HIGH |
|
The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.
|
|||||
| CVE-2023-38708 | 1 Pimcore | 1 Pimcore | 2024-11-21 | N/A | 6.3 MEDIUM |
|
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exists in the `AssetController::importServerFilesAction`, which allows an attacker to overwrite or modify sensitive files by manipulating the pimcore_log parameter.This can lead to potential denial of service---key file overwrite.
The impact of this vulnerability allows attackers to: overwrite or modify sensitive files, potentially leading to unauthorize ...
Show More |
|||||
| CVE-2023-38702 | 1 Eng | 1 Knowage | 2024-11-21 | N/A | 9.9 CRITICAL |
|
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/restful-services/dossier/importTemplateFile` allows authenticated users to upload `template file` on the server, but does not need any authorization to be reached. When the JSP file is uploaded, the attacker just needs to connect to `/knowageqbeengine/foo.jsp` to gain code execution on the server. By exploiting this vulnerability, an attacker with l ...
Show More |
|||||
| CVE-2023-38695 | 1 Simonsmith | 1 Cypress Image Snapshot | 2024-11-21 | N/A | 6.5 MEDIUM |
|
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.
|
|||||
| CVE-2023-38633 | 3 Debian, Fedoraproject, Gnome | 3 Debian Linux, Fedora, Librsvg | 2024-11-21 | N/A | 5.5 MEDIUM |
|
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
|
|||||
| CVE-2023-38399 | 2024-11-21 | N/A | 8.6 HIGH | ||
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Portfolio allows PHP Local File Inclusion.This issue affects Phlox Portfolio: from n/a through 2.3.1.
|
|||||
| CVE-2023-38346 | 1 Windriver | 1 Vxworks | 2024-11-21 | N/A | 8.8 HIGH |
|
An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behav ...
Show More |
|||||
| CVE-2023-38337 | 1 Rswag Project | 1 Rswag | 2024-11-21 | N/A | 7.5 HIGH |
|
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.
|
|||||
| CVE-2023-38312 | 1 Valvesoftware | 1 Counter-strike | 2024-11-21 | N/A | 7.5 HIGH |
|
A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary files from the underlying server via the motdfile console variable.
|
|||||
| CVE-2023-38256 | 1 Doverfuelingsolutions | 2 Maglink Lx 3, Maglink Lx Web Console Configuration | 2024-11-21 | N/A | 6.8 MEDIUM |
|
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3
vulnerable to a path traversal attack, which could allow an attacker to access files stored on the system.
|
|||||
| CVE-2023-38176 | 1 Microsoft | 1 Azure Arc-enabled Servers | 2024-11-21 | N/A | 7.0 HIGH |
|
Azure Arc-Enabled Servers Elevation of Privilege Vulnerability
|
|||||
| CVE-2023-38126 | 1 Softing | 1 Edgeaggregator | 2024-11-21 | N/A | 7.2 HIGH |
|
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability.
The specific flaw exists within the processing of backup zip files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this to e ...
Show More |
|||||
| CVE-2023-38019 | 1 Ibm | 1 Soar Qradar Plugin App | 2024-11-21 | N/A | 8.1 HIGH |
|
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.
|
|||||
| CVE-2023-37960 | 1 Jenkins | 1 Mathworks Polyspace | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jenkins controller file systems.
|
|||||
| CVE-2023-37932 | 1 Fortinet | 1 Fortivoice | 2024-11-21 | N/A | 6.5 MEDIUM |
|
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests
|
|||||
| CVE-2023-37913 | 1 Xwiki | 1 Xwiki | 2024-11-21 | N/A | 9.9 CRITICAL |
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering the office converter with a specially crafted file name allows writing the attachment's content to an attacker-controlled location on the server as long as the Java process has write access to that location. In particular in the combination with attachment moving, a feature introduced in XWiki 14.0, th ...
Show More |
|||||
| CVE-2023-37896 | 1 Projectdiscovery | 1 Nuclei | 2024-11-21 | N/A | 7.5 HIGH |
|
Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This issue did not affect CLI users. The problem was related to sanitization issues with payload loading in sandbox mode. There was a potential risk with payloads loading in sandbox mode. The issue occurred due to relative paths not being converted to absolute paths before doing the check for `sandbox` flag allowing arbitrary ...
Show More |
|||||
| CVE-2023-37781 | 1 Emqx | 1 Emqx | 2024-11-21 | N/A | 6.5 MEDIUM |
|
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.
|
|||||
| CVE-2023-37739 | 1 I-doit | 1 I-doit | 2024-11-21 | N/A | 6.5 MEDIUM |
|
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
|
|||||
| CVE-2023-37646 | 1 Bitberry | 1 File Opener | 2024-11-21 | N/A | 7.8 HIGH |
|
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
|
|||||
| CVE-2023-37601 | 1 Mobisystems | 1 Office Suite | 2024-11-21 | N/A | 7.5 HIGH |
|
Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.
|
|||||
| CVE-2023-37532 | 1 Hcltech | 1 Commerce | 2024-11-21 | N/A | 5.8 MEDIUM |
|
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
|
|||||
| CVE-2023-37461 | 1 Metersphere | 1 Metersphere | 2024-11-21 | N/A | 5.6 MEDIUM |
|
Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../` which may cause metersphere to attempt to overwrite an existing file in the defined location or to create a new file. Attackers would be limited to overwriting files that the metersphere process has access to. This issue has been addressed in version 2.10.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
|
|||||
| CVE-2023-37460 | 1 Codehaus-plexus | 1 Plexus-archiver | 2024-11-21 | N/A | 8.1 HIGH |
|
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the `resolveFile()` function will return the symlink's sou ...
Show More |
|||||
| CVE-2023-37428 | 1 Arubanetworks | 1 Edgeconnect Sd-wan Orchestrator | 2024-11-21 | N/A | 7.2 HIGH |
|
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
|
|||||
| CVE-2023-37385 | 2024-11-21 | N/A | 7.3 HIGH | ||
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.
|
|||||
| CVE-2023-37288 | 1 Smartsoft | 1 Smartbpm.net | 2024-11-21 | N/A | 6.5 MEDIUM |
|
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
|
|||||