CWE-37 · 6 записей
Path Traversal: '/absolute/pathname/here'
CVE этого класса
6 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2022-20962Эксплойта нет | A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker tocisco · identity services engine · CWE-37 | Высокая8,8 | — | 1,0 % | 4 нояб. 2022 г. |
33Наблюдать | CVE-2022-25347Эксплойта нет | Delta Electronics DIAEnergie Path Traversaldeltaww · diaenergie · CWE-37 | Высокая7,5 | — | 11,4 % | 29 мар. 2022 г. |
26Наблюдать | CVE-2023-20077Эксплойта нет | Cisco Identity Services Engine Arbitrary File Download Vulnerabilitiescisco · identity services engine · CWE-37 | Средняя6,5 | — | 0,8 % | 17 мая 2023 г. |
26Наблюдать | CVE-2023-20087Эксплойта нет | Cisco Identity Services Engine Arbitrary File Download Vulnerabilitiescisco · identity services engine · CWE-37 | Средняя6,5 | — | 0,8 % | 17 мая 2023 г. |
22Наблюдать | CVE-2018-10498Эксплойта нет | This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.samsung · samsung email · CWE-37 | Средняя5,5 | — | 0,4 % | 24 сент. 2018 г. |
19Наблюдать | CVE-2024-12806Эксплойта нет | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.sonicwall · sonicos · CWE-37 | Средняя4,9 | — | 0,6 % | 9 янв. 2025 г. |
- CVE-2022-2096235Наблюдать
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cisco · identity services engine4 нояб. 2022 г.
- CVE-2022-2534733Наблюдать
Delta Electronics DIAEnergie Path Traversal
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %deltaww · diaenergie29 мар. 2022 г.
- CVE-2023-2007726Наблюдать
Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · identity services engine17 мая 2023 г.
- CVE-2023-2008726Наблюдать
Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · identity services engine17 мая 2023 г.
- CVE-2018-1049822Наблюдать
This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %samsung · samsung email24 сент. 2018 г.
- CVE-2024-1280619Наблюдать
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
СредняяCVSS 4,9Эксплойта нетEPSS 1 %sonicwall · sonicos9 янв. 2025 г.