Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-09-19 CVE-2022-40715 Path Traversal vulnerability in Nokia 1350 Optical Management System 14.2
An issue was discovered in NOKIA 1350OMS R14.2.
network
low complexity
nokia CWE-22
6.5
2022-09-17 CVE-2022-39210 Path Traversal vulnerability in Nextcloud
Nextcloud android is the official Android client for the Nextcloud home server platform.
local
low complexity
nextcloud CWE-22
5.5
2022-09-16 CVE-2022-39001 Path Traversal vulnerability in Huawei Emui, Harmonyos and Magic UI
The number identification module has a path traversal vulnerability.
network
low complexity
huawei CWE-22
7.5
2022-09-16 CVE-2022-34002 Path Traversal vulnerability in Pdssoftware PDS Vista 7
The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source code of the web application.
network
low complexity
pdssoftware CWE-22
6.5
2022-09-15 CVE-2022-1798 Path Traversal vulnerability in Kubevirt
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107.
local
low complexity
kubevirt CWE-22
6.5
2022-09-14 CVE-2022-40734 Path Traversal vulnerability in Unisharp Laravel Filemanager
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F..
network
low complexity
unisharp CWE-22
6.5
2022-09-14 CVE-2022-38301 Path Traversal vulnerability in Onedev Project Onedev 7.4.14
Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories via uploading a crafted JAR file into the directory /opt/onedev/lib.
network
low complexity
onedev-project CWE-22
8.8
2022-09-13 CVE-2022-20395 Path Traversal vulnerability in Google Android
In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error.
local
low complexity
google CWE-22
7.8
2022-09-13 CVE-2022-37703 Path Traversal vulnerability in Amanda 3.5.1
In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary.
local
low complexity
amanda CWE-22
3.3
2022-09-13 CVE-2022-32190 Path Traversal vulnerability in Golang GO 1.19.0
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path.
network
low complexity
golang CWE-22
7.5