Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-02-07 CVE-2022-22679 Path Traversal vulnerability in Synology Diskstation Manager
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.
network
low complexity
synology CWE-22
4.9
2022-02-04 CVE-2022-23609 Path Traversal vulnerability in Itunesrpc-Remastered Project Itunesrpc-Remastered 3.1.0
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility.
network
low complexity
itunesrpc-remastered-project CWE-22
critical
9.1
2022-02-04 CVE-2022-24348 Path Traversal vulnerability in Argoproj Argo CD
Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go.
network
low complexity
argoproj CWE-22
7.7
2022-02-04 CVE-2021-29395 Path Traversal vulnerability in Globalnorthstar Northstar Club Management 6.3
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.
network
low complexity
globalnorthstar CWE-22
7.5
2022-02-04 CVE-2021-29398 Path Traversal vulnerability in Globalnorthstar Northstar Club Management 6.3
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.
network
low complexity
globalnorthstar CWE-22
5.3
2022-02-04 CVE-2021-44977 Path Traversal vulnerability in Idreamsoft Icms
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
network
low complexity
idreamsoft CWE-22
7.5
2022-02-03 CVE-2022-23357 Path Traversal vulnerability in Mozilo Mozilocms 2.0
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
network
low complexity
mozilo CWE-22
critical
9.1
2022-02-02 CVE-2021-42753 Path Traversal vulnerability in Fortinet Fortiweb
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.
network
low complexity
fortinet CWE-22
8.1
2022-02-01 CVE-2022-23602 Path Traversal vulnerability in Nim-Lang Docutils and Nimforum
Nimforum is a lightweight alternative to Discourse written in Nim.
network
low complexity
nim-lang CWE-22
8.1
2022-01-31 CVE-2021-23520 Path Traversal vulnerability in Juce
The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp.
network
low complexity
juce CWE-22
critical
9.8