Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-09-19 CVE-2022-40608 Path Traversal vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the target machine by manipulating the URL with a directory traversal attack.
network
low complexity
ibm CWE-22
7.5
2022-09-19 CVE-2022-37700 Path Traversal vulnerability in Easycorp Zentao 15.0
Zentao Demo15 is vulnerable to Directory Traversal.
network
low complexity
easycorp CWE-22
7.5
2022-09-19 CVE-2022-40713 Path Traversal vulnerability in Nokia 1350 Optical Management System 14.2
An issue was discovered in NOKIA 1350OMS R14.2.
network
low complexity
nokia CWE-22
6.5
2022-09-19 CVE-2022-40715 Path Traversal vulnerability in Nokia 1350 Optical Management System 14.2
An issue was discovered in NOKIA 1350OMS R14.2.
network
low complexity
nokia CWE-22
6.5
2022-09-17 CVE-2022-39210 Path Traversal vulnerability in Nextcloud
Nextcloud android is the official Android client for the Nextcloud home server platform.
local
low complexity
nextcloud CWE-22
5.5
2022-09-16 CVE-2022-39001 Path Traversal vulnerability in Huawei Emui, Harmonyos and Magic UI
The number identification module has a path traversal vulnerability.
network
low complexity
huawei CWE-22
7.5
2022-09-16 CVE-2022-34002 Path Traversal vulnerability in Pdssoftware PDS Vista 7
The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application.
network
low complexity
pdssoftware CWE-22
6.5
2022-09-15 CVE-2022-1798 Path Traversal vulnerability in Kubevirt
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107.
local
low complexity
kubevirt CWE-22
6.5
2022-09-14 CVE-2022-40734 Path Traversal vulnerability in Unisharp Laravel Filemanager
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F..
network
low complexity
unisharp CWE-22
6.5
2022-09-14 CVE-2022-38301 Path Traversal vulnerability in Onedev Project Onedev 7.4.14
Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.
network
low complexity
onedev-project CWE-22
8.8