Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-07-15 CVE-2021-21586 Path Traversal vulnerability in Dell Wyse Management Suite
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability.
network
low complexity
dell CWE-22
6.5
2021-07-14 CVE-2021-22867 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site.
network
low complexity
github CWE-22
6.5
2021-07-14 CVE-2021-23407 Path Traversal vulnerability in Elfinder.Net.Core Project Elfinder.Net.Core
This affects the package elFinder.Net.Core from 0 and before 1.2.4.
network
low complexity
elfinder-net-core-project CWE-22
7.5
2021-07-14 CVE-2021-33211 Path Traversal vulnerability in Element-It Http Commander 5.3.3
A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives.
network
low complexity
element-it CWE-22
6.5
2021-07-13 CVE-2021-22440 Path Traversal vulnerability in Huawei products
There is a path traversal vulnerability in some Huawei products.
low complexity
huawei CWE-22
4.6
2021-07-12 CVE-2021-32746 Path Traversal vulnerability in Icinga
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface.
network
high complexity
icinga CWE-22
5.3
2021-07-12 CVE-2021-33807 Path Traversal vulnerability in Gespage
Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
network
low complexity
gespage CWE-22
7.5
2021-07-12 CVE-2021-24013 Path Traversal vulnerability in Fortinet Fortimail
Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via specifically crafted web requests.
network
low complexity
fortinet CWE-22
6.5
2021-07-07 CVE-2021-33215 Path Traversal vulnerability in Commscope Ruckus IOT Controller 1.7.1.0
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier.
network
low complexity
commscope CWE-22
4.3
2021-07-07 CVE-2020-24143 Path Traversal vulnerability in Ninjateam Video Downloader for Tiktok 1.3
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
network
low complexity
ninjateam CWE-22
7.5