Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-01-13 CVE-2022-42136 Path Traversal vulnerability in Mailenable
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access.
network
low complexity
mailenable CWE-22
8.8
2023-01-13 CVE-2022-45299 Path Traversal vulnerability in Webbrowser Project Webbrowser
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.
network
low complexity
webbrowser-project CWE-22
critical
9.8
2023-01-13 CVE-2022-3782 Path Traversal vulnerability in Redhat Keycloak 20.0.2
keycloak: path traversal via double URL encoding.
network
low complexity
redhat CWE-22
critical
9.1
2023-01-13 CVE-2022-42280 Path Traversal vulnerability in Nvidia BMC
NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead to authentication bypass.
local
low complexity
nvidia CWE-22
7.8
2023-01-11 CVE-2022-4885 Path Traversal vulnerability in Jefferson Project Jefferson 0.3
A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical.
network
high complexity
jefferson-project CWE-22
5.9
2023-01-11 CVE-2022-48253 Path Traversal vulnerability in Nazgul Nostromo
nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server.
network
low complexity
nazgul CWE-22
critical
9.8
2023-01-10 CVE-2016-15017 Path Traversal vulnerability in Ecodev Media Upload
A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical.
network
low complexity
ecodev CWE-22
critical
9.8
2023-01-10 CVE-2023-22320 Path Traversal vulnerability in Openam 4.1.0
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22).
network
low complexity
openam CWE-22
7.5
2023-01-09 CVE-2022-36928 Path Traversal vulnerability in Zoom
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability.
local
low complexity
zoom CWE-22
7.1
2023-01-09 CVE-2022-4884 Path Traversal vulnerability in Checkmk 2.0.0/2.1.0
Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files to arbitrary locations via a malicious mkp file.
network
low complexity
checkmk CWE-22
4.9