Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-02-11 CVE-2020-14523 Path Traversal vulnerability in Mitsubishielectric products
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
network
low complexity
mitsubishielectric CWE-22
critical
9.8
2022-02-11 CVE-2021-44111 Path Traversal vulnerability in S-Cart
A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.
local
low complexity
s-cart CWE-22
4.4
2022-02-10 CVE-2022-24647 Path Traversal vulnerability in Cuppacms 1.0
Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.
network
low complexity
cuppacms CWE-22
8.1
2022-02-09 CVE-2021-45286 Path Traversal vulnerability in Zzcms 2021
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.
network
low complexity
zzcms CWE-22
5.3
2022-02-08 CVE-2022-21193 Path Traversal vulnerability in Dounokouno Transmitmail 2.5.0/2.6.0/2.6.1
Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an arbitrary file on the server via unspecified vectors.
network
low complexity
dounokouno CWE-22
7.5
2022-02-07 CVE-2022-22931 Path Traversal vulnerability in Apache James 3.6.1
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations.
network
low complexity
apache CWE-22
4.3
2022-02-07 CVE-2022-22679 Path Traversal vulnerability in Synology Diskstation Manager
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.
network
low complexity
synology CWE-22
4.9
2022-02-04 CVE-2022-23609 Path Traversal vulnerability in Itunesrpc-Remastered Project Itunesrpc-Remastered 3.1.0
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility.
network
low complexity
itunesrpc-remastered-project CWE-22
critical
9.1
2022-02-04 CVE-2022-24348 Path Traversal vulnerability in Argoproj Argo CD
Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go.
network
low complexity
argoproj CWE-22
7.7
2022-02-04 CVE-2021-29395 Path Traversal vulnerability in Globalnorthstar Northstar Club Management 6.3
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
network
low complexity
globalnorthstar CWE-22
7.5