Vulnerabilities (CVE)

Filtered by CWE-29
Total 64 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-1034 1 Salesagility 1 Suitecrm 2026-06-17 N/A 8.8 HIGH
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
CVE-2023-0316 1 Froxlor 1 Froxlor 2026-06-17 N/A 5.5 MEDIUM
Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.
CVE-2023-0104 1 Weintek 1 Easybuilder Pro 2026-06-17 N/A 9.3 CRITICAL
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  
CVE-2022-2788 1 Emerson 1 Electric\'s Proficy 2026-06-17 N/A 3.9 LOW
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.