Vulnerabilities (CVE)

Filtered by CWE-22
Total 7119 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16774 1 Hongcms Project 1 Hongcms 2024-11-21 6.4 MEDIUM 7.5 HIGH
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.
CVE-2018-16739 1 Abus 94 Tvip 10000, Tvip 10000 Firmware, Tvip 10001 and 91 more 2024-11-21 N/A 8.8 HIGH
An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.
CVE-2018-16716 1 Nih 1 Ncbi Toolbox 2024-11-21 7.5 HIGH 9.1 CRITICAL
A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.
CVE-2018-16594 1 Sony 105 Kd-43xe7000, Kd-43xe7002, Kd-43xe7003 and 102 more 2024-11-21 4.8 MEDIUM 8.1 HIGH
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
CVE-2018-16549 1 Php File Browser Script Project 1 Php File Browser Script 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
CVE-2018-16518 1 Primx 2 Zed\!, Zed\! Free 2024-11-21 7.5 HIGH 9.8 CRITICAL
A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.
CVE-2018-16493 1 Static-resource-server Project 1 Static-resource-server 2024-11-21 5.0 MEDIUM 7.5 HIGH
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
CVE-2018-16485 1 M-server Project 1 M-server 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request.
CVE-2018-16482 1 Mcstatic Project 1 Mcstatic 2024-11-21 5.0 MEDIUM 7.5 HIGH
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.
CVE-2018-16479 1 Http-live-simulator Project 1 Http-live-simulator 2024-11-21 5.0 MEDIUM 7.5 HIGH
Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL.
CVE-2018-16478 1 Simplehttpserver Project 1 Simplehttpserver 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
CVE-2018-16475 1 Knight Project 1 Knight 2024-11-21 5.0 MEDIUM 7.5 HIGH
A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server.
CVE-2018-16473 1 Takeapeek Project 1 Takeapeek 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.
CVE-2018-16457 1 Open Source Real-estate Script Project 1 Open Source Real-estate Script 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.
CVE-2018-16446 1 Seamcms 1 Seacms 2024-11-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.
CVE-2018-16437 1 Gxlcms 1 Gxlcms 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
CVE-2018-16367 1 Qduoj 1 Onlinejudge 2024-11-21 9.0 HIGH 9.9 CRITICAL
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
CVE-2018-16344 1 Zzcms 1 Zzcms 2024-11-21 6.4 MEDIUM 7.5 HIGH
An issue was discovered in zzcms 8.3. It allows remote attackers to delete arbitrary files via directory traversal sequences in the flv parameter. This can be leveraged for database access by deleting install.lock.
CVE-2018-16320 1 Idreamsoft 1 Icms 2024-11-21 6.5 MEDIUM 7.2 HIGH
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
CVE-2018-16299 1 Localize My Post Project 1 Localize My Post 2024-11-21 5.0 MEDIUM 7.5 HIGH
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.