Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-10-21 CVE-2020-27304 Path Traversal vulnerability in multiple products
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API.
network
low complexity
civetweb-project siemens CWE-22
critical
9.8
2021-10-20 CVE-2021-42771 Path Traversal vulnerability in multiple products
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
local
low complexity
pocoo debian CWE-22
7.8
2021-10-19 CVE-2021-41150 Path Traversal vulnerability in Amazon Tough
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories.
network
low complexity
amazon CWE-22
6.5
2021-10-19 CVE-2021-42261 Path Traversal vulnerability in Revisorlab Video Management System
Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability.
network
low complexity
revisorlab CWE-22
7.5
2021-10-18 CVE-2021-41151 Path Traversal vulnerability in Linuxfoundation Backstage
Backstage is an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-22
4.9
2021-10-18 CVE-2021-41152 Path Traversal vulnerability in Frentix Openolat
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system.
network
low complexity
frentix CWE-22
7.7
2021-10-15 CVE-2021-40724 Path Traversal vulnerability in Adobe Acrobat Reader
Acrobat Reader for Android versions 21.8.0 (and earlier) are affected by a Path traversal vulnerability.
local
low complexity
adobe CWE-22
7.8
2021-10-15 CVE-2021-3874 Path Traversal vulnerability in Bookstackapp Bookstack
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
network
low complexity
bookstackapp CWE-22
6.5
2021-10-15 CVE-2021-40988 Path Traversal vulnerability in Arubanetworks Clearpass Policy Manager
A remote directory traversal vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1.
network
low complexity
arubanetworks CWE-22
7.2
2021-10-14 CVE-2021-33178 Path Traversal vulnerability in Nagvis
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability.
network
low complexity
nagvis CWE-22
6.5