Skip to main content

CWE archive

CWE-23 CVEs

Programmatic archive

457 CVEs tagged with CWE-2357 Critical, 203 High, 167 Medium, 30 Low, 0 Unrated.

CVE-2022-20862

Published Jul 6, 2022

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Uni…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2106

Published Jun 27, 2022

Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbit…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29097

Published Jun 24, 2022

Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2120

Published Jun 24, 2022

OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32964

Published May 24, 2022

The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34605

Published May 11, 2022

A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted pr…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20790

Published Apr 21, 2022

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Uni…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22279

Published Apr 13, 2022

A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 ser…

CVSS 4.9 · Medium

CVE-2022-20755

Published Apr 6, 2022

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authentic…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-20754

Published Apr 6, 2022

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authentic…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-23732

Published Apr 5, 2022

A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21808

Published Mar 11, 2022

Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP vers…

CVSS 8.8 · High

CVE-2022-21177

Published Mar 11, 2022

There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM…

CVSS 8.1 · High

CVE-2021-37196

Published Jan 11, 2022

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V1…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41242

Published Dec 10, 2021

OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20040

Published Dec 8, 2021

A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnera…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2021-43555

Published Nov 19, 2021

mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. Th…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22870

Published Nov 10, 2021

A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41178

Published Oct 25, 2021

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download ar…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 457 CVEsPage 16 of 19