Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2021-37729 Path Traversal vulnerability in multiple products
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.3, 8.6.0.9, 8.5.0.12, 8.3.0.16, 6.5.4.19, 6.4.4.25.
network
low complexity
arubanetworks siemens CWE-22
6.5
2021-09-07 CVE-2021-37731 Path Traversal vulnerability in multiple products
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16.
low complexity
arubanetworks siemens CWE-22
6.2
2021-09-07 CVE-2021-37733 Path Traversal vulnerability in multiple products
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.11, 8.3.0.16.
network
low complexity
arubanetworks siemens CWE-22
4.9
2021-09-07 CVE-2021-36717 Path Traversal vulnerability in Synerion Timenet 9.21
Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file.
network
low complexity
synerion CWE-22
7.5
2021-09-01 CVE-2021-23427 Path Traversal vulnerability in Elfinder.Netcore Project Elfinder.Netcore
This affects all versions of package elFinder.NetCore.
network
low complexity
elfinder-netcore-project CWE-22
critical
9.8
2021-09-01 CVE-2021-23428 Path Traversal vulnerability in Elfinder.Netcore Project Elfinder.Netcore
This affects all versions of package elFinder.NetCore.
network
low complexity
elfinder-netcore-project CWE-22
critical
9.8
2021-09-01 CVE-2021-39109 Path Traversal vulnerability in Atlassian Atlasboard
The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.
network
low complexity
atlassian CWE-22
7.5
2021-08-31 CVE-2021-39180 Path Traversal vulnerability in Frentix Openolat
OpenOLAT is a web-based learning management system (LMS).
network
low complexity
frentix CWE-22
8.8
2021-08-30 CVE-2020-18127 Path Traversal vulnerability in Indexhibit 2.1.5
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
network
low complexity
indexhibit CWE-22
6.5
2021-08-30 CVE-2021-22022 Path Traversal vulnerability in VMWare products
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability.
network
low complexity
vmware CWE-22
4.9