Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-23 Clear
ID Title
CVE-2026-21620 Vulnerability in path-traversal (CVE-2026-21620)
vulnerability in path-traversal (CVE-2026-21620). Risk of unauthorized operations or information disclosure.
CVE-2025-66737 Vulnerability in path-traversal (CVE-2025-66737)
vulnerability in path-traversal (CVE-2025-66737). Risk of unauthorized operations or information disclosure.
CVE-2025-64446 KEV [KEV] Vulnerability in Fortinet fortiweb (CVE-2025-64446)
vulnerability in Fortinet fortiweb (CVE-2025-64446). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-55752 Vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.0.109, 10.1.45, 11.0.11` or later.
CVE-2025-51052 Vulnerability in path-traversal (CVE-2025-51052)
vulnerability in path-traversal (CVE-2025-51052). Risk of unauthorized operations or information disclosure.
CVE-2024-43454 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38258 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
CVE-2023-42456 Path Traversal in sudo-rs (CVE-2023-42456)
path traversal in sudo-rs (CVE-2023-42456). Risk of unauthorized operations or information disclosure. Exploitable via ``useradd``. Mitigation: upgrade to `0.2.1` or later.
CVE-2023-38185 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-35359 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23391 Office for Android Spoofing Vulnerability
Office for Android Spoofing Vulnerability
CVE-2023-23379 Microsoft Defender for IoT Elevation of Privilege Vulnerability
Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2022-37042 KEV [KEV] Path Traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-37042)
path traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-37042). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-38163 KEV [KEV] Vulnerability in Sap netweaver (CVE-2021-38163)
vulnerability in Sap netweaver (CVE-2021-38163). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-5410 KEV [KEV] Vulnerability in Vmware tanzu vmware-tanzu (CVE-2020-5410)
vulnerability in Vmware tanzu vmware-tanzu (CVE-2020-5410). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-22017 KEV [KEV] Vulnerability in Vmware vcenter-server (CVE-2021-22017)
vulnerability in Vmware vcenter-server (CVE-2021-22017). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-22005 KEV [KEV] Vulnerability in Vmware vcenter-server (CVE-2021-22005)
vulnerability in Vmware vcenter-server (CVE-2021-22005). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-21972 KEV [KEV] Path Traversal in Vmware vcenter-server (CVE-2021-21972)
path traversal in Vmware vcenter-server (CVE-2021-21972). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-13996 Vulnerability in path-traversal (CVE-2017-13996)
vulnerability in path-traversal (CVE-2017-13996). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →