Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-11-12 CVE-2021-43496 Path Traversal vulnerability in Clustering Project Clustering 20190726
Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability.
network
low complexity
clustering-project CWE-22
7.5
2021-11-11 CVE-2021-34422 Path Traversal vulnerability in Keybase
The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder.
network
low complexity
keybase CWE-22
critical
9.0
2021-11-11 CVE-2021-3907 Path Traversal vulnerability in multiple products
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex.
network
low complexity
cloudflare debian CWE-22
critical
9.8
2021-11-10 CVE-2021-22870 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files.
network
low complexity
github CWE-22
6.5
2021-11-09 CVE-2021-42021 Path Traversal vulnerability in Siemens products
A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020 R3), Siveillance Video DLNA Server (2021 R1).
network
low complexity
siemens CWE-22
7.5
2021-11-04 CVE-2021-21690 Path Traversal vulnerability in Jenkins
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
network
low complexity
jenkins CWE-22
critical
9.8
2021-11-04 CVE-2021-21692 Path Traversal vulnerability in Jenkins
FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of 'delete'.
network
low complexity
jenkins CWE-22
critical
9.8
2021-11-04 CVE-2021-21698 Path Traversal vulnerability in Jenkins Subversion
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
network
low complexity
jenkins CWE-22
7.5
2021-11-04 CVE-2021-34701 Path Traversal vulnerability in Cisco Unified Communications Manager
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access sensitive data on an affected device.
network
low complexity
cisco CWE-22
4.3
2021-11-04 CVE-2021-34594 Path Traversal vulnerability in Beckhoff Tf6100 Firmware and Ts6100 Firmware
TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.
network
low complexity
beckhoff CWE-22
6.5