Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-33497 Path Traversal vulnerability in Dutchcoders Transfer.Sh
Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.
network
low complexity
dutchcoders CWE-22
critical
9.1
2021-05-21 CVE-2020-23766 Path Traversal vulnerability in Htmly 2.7.5
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
network
low complexity
htmly CWE-22
6.5
2021-05-21 CVE-2021-32633 Path Traversal vulnerability in multiple products
Zope is an open-source web application server.
network
low complexity
plone zope CWE-22
8.8
2021-05-21 CVE-2021-28798 Path Traversal vulnerability in Qnap QTS and Quts Hero
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-22
7.5
2021-05-20 CVE-2020-21055 Path Traversal vulnerability in Fusionpbx 4.5.7
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
network
low complexity
fusionpbx CWE-22
6.5
2021-05-20 CVE-2020-21056 Path Traversal vulnerability in Fusionpbx 4.5.7
Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.
network
low complexity
fusionpbx CWE-22
4.3
2021-05-20 CVE-2020-21057 Path Traversal vulnerability in Fusionpbx 4.5.7
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.
network
low complexity
fusionpbx CWE-22
8.1
2021-05-20 CVE-2020-35580 Path Traversal vulnerability in Searchblox
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request.
network
low complexity
searchblox CWE-22
7.5
2021-05-20 CVE-2021-3426 Path Traversal vulnerability in multiple products
There's a flaw in Python 3's pydoc.
5.7
2021-05-19 CVE-2020-36364 Path Traversal vulnerability in Smartstore Smartstorenet
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0.
network
low complexity
smartstore CWE-22
critical
9.1