Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-10-18 CVE-2021-41152 Path Traversal vulnerability in Frentix Openolat
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system.
network
low complexity
frentix CWE-22
7.7
2021-10-15 CVE-2021-40724 Path Traversal vulnerability in Adobe Acrobat Reader
Acrobat Reader for Android versions 21.8.0 (and earlier) are affected by a Path traversal vulnerability.
local
low complexity
adobe CWE-22
7.8
2021-10-15 CVE-2021-3874 Path Traversal vulnerability in Bookstackapp Bookstack
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
network
low complexity
bookstackapp CWE-22
6.5
2021-10-15 CVE-2021-40988 Path Traversal vulnerability in Arubanetworks Clearpass Policy Manager
A remote directory traversal vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1.
network
low complexity
arubanetworks CWE-22
7.2
2021-10-14 CVE-2021-33178 Path Traversal vulnerability in Nagvis
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability.
network
low complexity
nagvis CWE-22
6.5
2021-10-13 CVE-2021-20123 Path Traversal vulnerability in Draytek Vigorconnect 1.6.0
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint.
network
low complexity
draytek CWE-22
7.5
2021-10-13 CVE-2021-20124 Path Traversal vulnerability in Draytek Vigorconnect 1.6.0
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint.
network
low complexity
draytek CWE-22
7.5
2021-10-13 CVE-2021-20796 Path Traversal vulnerability in Cybozu Remote Service Manager 3.1.8
Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.
network
low complexity
cybozu CWE-22
6.5
2021-10-12 CVE-2021-37734 Path Traversal vulnerability in multiple products
A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.19 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below; Aruba Instant 8.8.x.x: 8.8.0.0 and below.
network
low complexity
arubanetworks siemens CWE-22
6.5
2021-10-12 CVE-2021-38454 Path Traversal vulnerability in Moxa Mxview
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
network
low complexity
moxa CWE-22
critical
10.0