Vulnerabilities (CVE)

Filtered by CWE-22
Total 6174 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23314 1 Zdir Project 1 Zdir 2023-01-30 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file.
CVE-2021-3762 1 Redhat 2 Clair, Quay 2023-01-30 7.5 HIGH 9.8 CRITICAL
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
CVE-2019-11822 1 Synology 1 Photo Station 2023-01-30 4.0 MEDIUM 6.5 MEDIUM
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
CVE-2022-43975 1 Ge 2 Ms 3000, Ms 3000 Firmware 2023-01-30 N/A 7.5 HIGH
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.
CVE-2022-46959 1 Sonic Project 1 Sonic 2023-01-30 N/A 4.3 MEDIUM
An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal.
CVE-2019-11826 1 Synology 1 Moments 2023-01-30 6.5 MEDIUM 8.8 HIGH
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
CVE-2018-20470 1 Sahipro 1 Sahi Pro 2023-01-30 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.
CVE-2018-3731 1 Public.js Project 1 Public.js 2023-01-30 5.0 MEDIUM 7.5 HIGH
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
CVE-2018-3725 1 Hekto Project 1 Hekto 2023-01-30 5.0 MEDIUM 7.5 HIGH
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.
CVE-2019-4384 1 Ibm 1 Campaign 2023-01-30 4.0 MEDIUM 4.3 MEDIUM
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.
CVE-2018-3744 1 Html-pages Project 1 Html-pages 2023-01-30 5.0 MEDIUM 9.8 CRITICAL
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
CVE-2018-3730 1 Mcstatic Project 1 Mcstatic 2023-01-30 5.0 MEDIUM 7.5 HIGH
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.
CVE-2018-3715 1 Glance Project 1 Glance 2023-01-30 4.0 MEDIUM 6.5 MEDIUM
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
CVE-2018-3734 1 Stattic Project 1 Stattic 2023-01-30 5.0 MEDIUM 7.5 HIGH
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.
CVE-2018-3758 1 Express-cart Project 1 Express-cart 2023-01-30 9.0 HIGH 8.8 HIGH
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
CVE-2020-15050 1 Supremainc 1 Biostar 2 2023-01-27 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.
CVE-2020-14461 1 Zyxel 2 Wap6806, Wap6806 Firmware 2023-01-27 5.0 MEDIUM 8.6 HIGH
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
CVE-2021-37500 1 Reprisesoftware 1 Reprise License Manager 2023-01-27 N/A 8.1 HIGH
Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.
CVE-2022-47747 1 Uber 1 Kraken 2023-01-27 N/A 7.5 HIGH
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
CVE-2023-0126 1 Sonicwall 2 Sma1000, Sma1000 Firmware 2023-01-26 N/A 7.5 HIGH
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.