Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-45593 Path Traversal vulnerability in Nixos NIX
Nix is a package manager for Linux and other Unix systems.
network
low complexity
nixos CWE-22
8.8
2024-09-10 CVE-2024-21753 Path Traversal vulnerability in Fortinet Forticlient Endpoint Management Server
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited number of files via specially crafted HTTP requests
network
low complexity
fortinet CWE-22
6.0
2024-09-09 CVE-2024-8585 Path Traversal vulnerability in Learningdigital Orca HCM
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
network
low complexity
learningdigital CWE-22
6.5
2024-09-07 CVE-2024-8538 Path Traversal vulnerability in Infiniteuploads BIG File Uploads
The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2.
network
low complexity
infiniteuploads CWE-22
4.3
2024-09-06 CVE-2023-51366 Path Traversal vulnerability in Qnap QTS and Quts Hero
A path traversal vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-22
6.5
2024-09-06 CVE-2024-21904 Path Traversal vulnerability in Qnap QTS and Quts Hero
A path traversal vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-22
6.5
2024-09-06 CVE-2024-6445 Path Traversal vulnerability in Dataflowx Datadiodex
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: from v3.0.0 before v3.1.7.
network
low complexity
dataflowx CWE-22
7.5
2024-09-05 CVE-2024-45401 Path Traversal vulnerability in Stripe Stripe-Cli
stripe-cli is a command-line tool for the payment processor Stripe.
local
low complexity
stripe CWE-22
7.1
2024-09-04 CVE-2024-45074 Path Traversal vulnerability in IBM Webmethods Integration 10.15
IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5
2024-09-04 CVE-2024-8409 Path Traversal vulnerability in Abcd-Community Abcd 2.2.0
A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1.
network
low complexity
abcd-community CWE-22
7.5