Filtered by CWE-35
Total 43 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-6252 1 Hyphensolutions 1 Chameleon Power 2024-08-02 7.5 High
Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read files located on the server and gain access to sensitive information such as configuration files.
CVE-2024-39171 1 Phpvibe 1 Phpvibe 2024-08-02 8.8 High
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
CVE-2024-2863 2024-08-01 5.3 Medium
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.