Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-12-27 CVE-2020-20944 Path Traversal vulnerability in Qibosoft 7.0
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
network
low complexity
qibosoft CWE-22
critical
9.1
2021-12-26 CVE-2021-45712 Path Traversal vulnerability in Rust-Embed Project Rust-Embed
An issue was discovered in the rust-embed crate before 6.3.0 for Rust.
network
low complexity
rust-embed-project CWE-22
7.5
2021-12-24 CVE-2021-20876 Path Traversal vulnerability in Groupsession
Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site's server via unspecified vectors.
network
low complexity
groupsession CWE-22
6.8
2021-12-23 CVE-2021-44548 Path Traversal vulnerability in Apache Solr
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network.
network
low complexity
apache CWE-22
critical
9.8
2021-12-22 CVE-2021-21879 Path Traversal vulnerability in Lantronix Premierwave 2050 8.9.0.0
A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
8.8
2021-12-22 CVE-2021-21880 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
7.2
2021-12-22 CVE-2021-21885 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
7.2
2021-12-22 CVE-2021-21886 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
4.3
2021-12-22 CVE-2021-21894 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU).
network
low complexity
lantronix CWE-22
critical
9.1
2021-12-22 CVE-2021-21895 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU).
network
low complexity
lantronix CWE-22
7.2