Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-01-14 CVE-2022-22054 Path Traversal vulnerability in Asus Rt-Ax56U Firmware 3.0.0.4.386.44266
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.
low complexity
asus CWE-22
6.5
2022-01-13 CVE-2022-21682 Path Traversal vulnerability in multiple products
Flatpak is a Linux application sandboxing and distribution framework.
network
low complexity
flatpak fedoraproject redhat debian CWE-22
6.5
2022-01-13 CVE-2021-23514 Path Traversal vulnerability in Crowcpp Crow
This affects the package Crow before 0.3+4.
network
low complexity
crowcpp CWE-22
7.5
2022-01-12 CVE-2022-23107 Path Traversal vulnerability in Jenkins Warnings Next Generation
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.
network
low complexity
jenkins CWE-22
8.1
2022-01-12 CVE-2022-23113 Path Traversal vulnerability in Jenkins Publish Over SSH
Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present or not, resulting in a path traversal vulnerability allowing attackers with Item/Configure permission to discover the name of the Jenkins controller files.
network
low complexity
jenkins CWE-22
4.3
2022-01-12 CVE-2022-21675 Path Traversal vulnerability in Bytecode Viewer Project Bytecode Viewer 2.10.16
Bytecode Viewer (BCV) is a Java/Android reverse engineering suite.
local
low complexity
bytecode-viewer-project CWE-22
7.8
2022-01-12 CVE-2021-28376 Path Traversal vulnerability in Chronoengine Chronoforums 7.0.7
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
network
low complexity
chronoengine CWE-22
2.7
2022-01-12 CVE-2021-28377 Path Traversal vulnerability in Chronoengine Chronoforums 2.0.11
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
network
low complexity
chronoengine CWE-22
5.3
2022-01-11 CVE-2021-37196 Path Traversal vulnerability in Siemens Comos
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.3 (All versions >= V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used).
network
low complexity
siemens CWE-22
6.5
2022-01-10 CVE-2021-44586 Path Traversal vulnerability in Dst-Admin Project Dst-Admin 1.3.0
An issue was discovered in dst-admin v1.3.0.
network
low complexity
dst-admin-project CWE-22
7.5