Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-06-07 CVE-2021-23391 Path Traversal vulnerability in Calipso Project Calipso
This affects all versions of package calipso.
local
low complexity
calipso-project CWE-22
7.1
2021-06-07 CVE-2021-33896 Path Traversal vulnerability in multiple products
Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.
network
low complexity
dino fedoraproject CWE-22
5.3
2021-06-07 CVE-2021-20517 Path Traversal vulnerability in IBM Websphere Application Server ND
IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories.
network
low complexity
ibm CWE-22
8.8
2021-06-04 CVE-2020-36142 Path Traversal vulnerability in Bloofox Bloofoxcms 0.5.2.1
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
network
low complexity
bloofox CWE-22
6.5
2021-06-02 CVE-2020-6950 Path Traversal vulnerability in multiple products
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
network
low complexity
eclipse oracle CWE-22
6.5
2021-06-01 CVE-2021-33182 Path Traversal vulnerability in Synology Diskstation Manager
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors.
network
low complexity
synology CWE-22
4.3
2021-05-27 CVE-2021-32643 Path Traversal vulnerability in Typelevel Http4S
Http4s is a Scala interface for HTTP services.
network
low complexity
typelevel CWE-22
5.8
2021-05-25 CVE-2021-29695 Path Traversal vulnerability in IBM products
IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5
2021-05-24 CVE-2020-20907 Path Traversal vulnerability in Metinfo 7.0.0
MetInfo 7.0 beta is affected by a file modification vulnerability.
network
low complexity
metinfo CWE-22
critical
9.1
2021-05-24 CVE-2021-21001 Path Traversal vulnerability in Wago products
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
network
low complexity
wago CWE-22
6.5