• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-22

CVE-2021-28584

February 23, 2023 by

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrary file system write by an authenticated attacker. Access to the admin console is required for successful exploitation.

CVE-2021-28588

February 23, 2023 by

Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

CVE-2021-28376

February 23, 2023 by

ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

CVE-2021-28377

February 23, 2023 by

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

CVE-2021-28205

February 23, 2023 by

The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

CVE-2021-28206

February 23, 2023 by

The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 378
  • Go to page 379
  • Go to page 380
  • Go to page 381
  • Go to page 382
  • Interim pages omitted …
  • Go to page 514
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE