Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,793 CVEs tagged with CWE-221,301 Critical, 4,052 High, 4,009 Medium, 425 Low, 6 Unrated.

CVE-2018-9851

Published Apr 8, 2018

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9850

Published Apr 8, 2018

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9331

Published Apr 7, 2018

An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leverag…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9205

Published Apr 4, 2018

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-6660

Published Apr 2, 2018

Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be us…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9159

Published Mar 31, 2018

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and director…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7171

Published Mar 30, 2018

Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3822

Published Mar 30, 2018

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been ab…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9117

Published Mar 29, 2018

WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application directory via a specially crafted XML re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9110

Published Mar 28, 2018

Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9109

Published Mar 28, 2018

Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1266

Published Mar 27, 2018

Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the locat…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12815

Published Mar 26, 2018

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1204

Published Mar 26, 2018

Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a path traversal vulnerab…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-8969

Published Mar 24, 2018

An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an actio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8968

Published Mar 24, 2018

An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8965

Published Mar 24, 2018

An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1211

Published Mar 23, 2018

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0542

Published Mar 22, 2018

Directory traversal vulnerability in WebProxy version 1.7.8 allows an attacker to read arbitrary files via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8909

Published Mar 22, 2018

The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 7,451-7,475 of 9,793 CVEsPage 299 of 392