Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-10-29 CVE-2020-25881 Path Traversal vulnerability in Ranko Rkcms
A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=../../../../111.txt&filetype=image/jpeg of the master version of RKCMS.
local
low complexity
ranko CWE-22
5.5
2021-10-28 CVE-2021-3823 Path Traversal vulnerability in Bitdefender Gravityzone
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances.
network
low complexity
bitdefender CWE-22
critical
9.8
2021-10-28 CVE-2021-22404 Path Traversal vulnerability in Huawei Emui and Magic UI
There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-22
5.3
2021-10-27 CVE-2021-34762 Path Traversal vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device.
network
low complexity
cisco CWE-22
8.1
2021-10-27 CVE-2021-37124 Path Traversal vulnerability in Huawei PC Smart Full Scene and Pcmanager
There is a path traversal vulnerability in Huawei PC product.
low complexity
huawei CWE-22
6.5
2021-10-27 CVE-2021-37130 Path Traversal vulnerability in Huawei Fusioncube Firmware 6.0.2
There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname.
network
low complexity
huawei CWE-22
7.5
2021-10-26 CVE-2019-3556 Path Traversal vulnerability in Facebook Hhvm
HHVM supports the use of an "admin" server which accepts administrative requests over HTTP.
network
low complexity
facebook CWE-22
8.1
2021-10-25 CVE-2021-40371 Path Traversal vulnerability in Gridprosoftware Request Management
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
network
low complexity
gridprosoftware CWE-22
critical
9.8
2021-10-22 CVE-2020-23038 Path Traversal vulnerability in Kumilabs Swift File Transfer
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter.
network
low complexity
kumilabs CWE-22
7.5
2021-10-22 CVE-2020-23040 Path Traversal vulnerability in SKY File Project SKY File 2.1.0
Sky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files via 'null' path commands.
network
low complexity
sky-file-project CWE-22
7.5