Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2022-25267 Path Traversal vulnerability in Passwork
Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).
network
low complexity
passwork CWE-22
8.8
2022-03-23 CVE-2021-27471 Path Traversal vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
The parsing mechanism that processes certain file types does not provide input sanitization for file paths.
local
low complexity
rockwellautomation CWE-22
8.6
2022-03-23 CVE-2021-27473 Path Traversal vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction.
local
low complexity
rockwellautomation CWE-22
8.2
2022-03-22 CVE-2022-24774 Path Traversal vulnerability in Cyclonedx Bill of Materials Repository Server
CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs.
network
low complexity
cyclonedx CWE-22
8.1
2022-03-21 CVE-2022-23347 Path Traversal vulnerability in Bigantsoft Bigant Server 5.6.06
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
network
low complexity
bigantsoft CWE-22
7.5
2022-03-21 CVE-2022-26960 Path Traversal vulnerability in Std42 Elfinder
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.
network
low complexity
std42 CWE-22
critical
9.1
2022-03-18 CVE-2020-25176 Path Traversal vulnerability in multiple products
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system.
network
low complexity
schneider-electric rockwellautomation xylem CWE-22
critical
9.8
2022-03-18 CVE-2021-45967 Path Traversal vulnerability in multiple products
An issue was discovered in Pascom Cloud Phone System before 7.20.x.
network
low complexity
pascom igniterealtime CWE-22
critical
9.8
2022-03-17 CVE-2022-26500 Path Traversal vulnerability in Veeam Backup & Replication
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
network
low complexity
veeam CWE-22
8.8
2022-03-17 CVE-2022-21221 Path Traversal vulnerability in Fasthttp Project Fasthttp
The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization.
network
low complexity
fasthttp-project CWE-22
7.5