Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-12-17 CVE-2021-23797 Path Traversal vulnerability in Http-Server-Node Project Http-Server-Node
All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
network
low complexity
http-server-node-project CWE-22
critical
9.8
2021-12-17 CVE-2021-32498 Path Traversal vulnerability in Sick Sopas Engineering Tool
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system.
local
low complexity
sick CWE-22
8.6
2021-12-16 CVE-2021-3960 Path Traversal vulnerability in Bitdefender Gravityzone 3.3.8.249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances.
local
low complexity
bitdefender CWE-22
7.8
2021-12-15 CVE-2021-43831 Path Traversal vulnerability in Gradio Project Gradio
Gradio is an open source framework for building interactive machine learning models and demos.
network
low complexity
gradio-project CWE-22
7.7
2021-12-15 CVE-2021-45043 Path Traversal vulnerability in Hd-Network Real-Time Monitoring System Project Hd-Network Real-Time Monitoring System 2.0
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
7.5
2021-12-14 CVE-2021-44232 Path Traversal vulnerability in SAP Saf-T Framework
SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access.
network
low complexity
sap CWE-22
7.7
2021-12-14 CVE-2021-45015 Path Traversal vulnerability in Taogogo Taocms 3.0.2
taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72.
network
low complexity
taogogo CWE-22
critical
9.1
2021-12-14 CVE-2021-41547 Path Traversal vulnerability in Siemens Teamcenter Active Workspace
A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3).
network
low complexity
siemens CWE-22
7.2
2021-12-13 CVE-2021-44965 Path Traversal vulnerability in PHPgurukul Employee Record Management System 1.2
Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.
network
low complexity
phpgurukul CWE-22
7.5
2021-12-13 CVE-2021-40858 Path Traversal vulnerability in Auerswald products
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure.
network
low complexity
auerswald CWE-22
4.9