Skip to main content

CWE archive

CWE-23 CVEs

Programmatic archive

457 CVEs tagged with CWE-2357 Critical, 203 High, 167 Medium, 30 Low, 0 Unrated.

CVE-2025-23011

Published Jan 23, 2025

Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will ext…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46664

Published Jan 14, 2025

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32115

Published Jan 14, 2025

A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the under…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0390

Published Jan 11, 2025

A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHC…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-0225

Published Jan 5, 2025

A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality o…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2024-13130

Published Jan 5, 2025

A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some u…

CVSS 5.3 · Medium

CVE-2024-12897

Published Dec 23, 2024

A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part o…

CVSS 5.3 · Medium

CVE-2023-34990

Published Dec 18, 2024

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted w…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-12645

Published Dec 16, 2024

The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the targ…

CVSS 6.5 · Medium

CVE-2024-12642

Published Dec 16, 2024

TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12482

Published Dec 12, 2024

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\wetech-basi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54154

Published Dec 4, 2024

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11315

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11314

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11313

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11312

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11311

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11310

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11309

Published Nov 18, 2024

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11067

Published Nov 11, 2024

The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50453

Published Oct 28, 2024

Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pack Elementor addons: from n/a t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 226-250 of 457 CVEsPage 10 of 19