Falhas do tipo CWE-23

424 resultados
CVE-2023-1044MEDIUMMuYuCMS index.php path traversalEPSS 1.1%CVE-2026-52813CRITICALGogs: Path Traversal in organization name results in RCE through Git hooksEPSS 1.1%CVE-2020-1904A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directoEPSS 1.1%CVE-2021-22870Path traversal in GitHub Enterprise Server hosted Pages leads to unauthorized file read accessEPSS 1.1%CVE-2021-34594MEDIUMBeckhoff: Relative path traversal vulnerability through TwinCAT OPC UA ServerEPSS 1.1%CVE-2021-22674The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and direEPSS 1.1%CVE-2023-37913CRITICALorg.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converterEPSS 1.1%CVE-2020-7377HIGHRapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump moduleEPSS 1.1%CVE-2025-27610HIGHLocal File Inclusion in Rack::StaticEPSS 1.1%CVE-2022-28814CRITICALPath traversal in Carlo Gavazzi UWP 3.0 could lead to full device accessEPSS 1.1%CVE-2021-32949HIGHMDT AutoSave Relative Path TraversalEPSS 1.1%CVE-2023-50255CRITICALZip Path Traversal in Deepin-CompressorEPSS 1.1%CVE-2023-46119HIGHParse Server may crash when uploading file without extensionEPSS 1.1%CVE-2022-1648MEDIUMRelative Path Traversal to Remote Code Execution in File ManagerEPSS 1.0%CVE-2023-4760HIGHRemote Code Execution in Eclipse RAP on WindowsEPSS 1.0%CVE-2022-22279A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versionEPSS 1.0%CVE-2018-12476MEDIUMobs-service-extract_file's outfilename parameter allows to write files outside of package directoryEPSS 1.0%CVE-2024-32115MEDIUMA relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged EPSS 1.0%CVE-2021-22650HIGHOvarro TBox Relative Path TraversalEPSS 1.0%CVE-2025-32409HIGHRatta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) cEPSS 1.0%