Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-02-21 CVE-2021-27753 Path Traversal vulnerability in Hcltech HCL Sametime
"Sametime Android PathTraversal Vulnerability"
local
low complexity
hcltech CWE-22
5.5
2022-02-21 CVE-2021-27755 Path Traversal vulnerability in Hcltech HCL Sametime
"Sametime Android potential path traversal vulnerability when using File class"
local
low complexity
hcltech CWE-22
5.5
2022-02-18 CVE-2022-25358 Path Traversal vulnerability in Awful-Salmonella-Tar Project Awful-Salmonella-Tar 0.0.2/0.0.3
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4.
network
low complexity
awful-salmonella-tar-project CWE-22
5.3
2022-02-18 CVE-2021-40841 Path Traversal vulnerability in Liveconfig
A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the underlying server.
network
low complexity
liveconfig CWE-22
6.5
2022-02-18 CVE-2021-26619 Path Traversal vulnerability in Bigfile Bigfileagent
An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent.
network
low complexity
bigfile CWE-22
critical
9.1
2022-02-18 CVE-2022-0673 Path Traversal vulnerability in Eclipse Lemminx
A flaw was found in LemMinX in versions prior to 0.19.0.
network
low complexity
eclipse CWE-22
6.5
2022-02-18 CVE-2022-25298 Path Traversal vulnerability in Webcc Project Webcc 0.2.0
This affects the package sprinfall/webcc before 0.3.0.
network
low complexity
webcc-project CWE-22
7.5
2022-02-17 CVE-2022-22914 Path Traversal vulnerability in Ovidentia 6.0.0
An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.
network
low complexity
ovidentia CWE-22
7.5
2022-02-16 CVE-2022-24983 Path Traversal vulnerability in Jqueryform
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response.
network
low complexity
jqueryform CWE-22
7.5
2022-02-15 CVE-2021-35380 Path Traversal vulnerability in Solari Termtalk Server 3.24.0.2
A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).
network
low complexity
solari CWE-22
7.5