Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-04-07 CVE-2020-24136 Path Traversal vulnerability in Wcms 0.3.2
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php.
network
low complexity
wcms CWE-22
8.6
2021-04-07 CVE-2021-20692 Path Traversal vulnerability in Eikisoft Archive Collectively Operation Utility
Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker to create or overwrite files by leading a user to expand a malicious ZIP archives.
local
low complexity
eikisoft CWE-22
7.1
2021-04-06 CVE-2020-13419 Path Traversal vulnerability in Openiam
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
network
low complexity
openiam CWE-22
5.3
2021-04-06 CVE-2021-28658 Path Traversal vulnerability in multiple products
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names.
network
low complexity
djangoproject debian fedoraproject CWE-22
5.3
2021-04-06 CVE-2021-28172 Path Traversal vulnerability in Deltaflow Project Deltaflow
There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform.
network
low complexity
deltaflow-project CWE-22
7.5
2021-04-06 CVE-2021-28209 Path Traversal vulnerability in Asus products
The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter.
network
low complexity
asus CWE-22
4.9
2021-04-06 CVE-2021-28208 Path Traversal vulnerability in Asus products
The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter.
network
low complexity
asus CWE-22
4.9
2021-04-06 CVE-2021-28207 Path Traversal vulnerability in Asus products
The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter.
network
low complexity
asus CWE-22
4.9
2021-04-06 CVE-2021-28206 Path Traversal vulnerability in Asus products
The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter.
network
low complexity
asus CWE-22
4.9
2021-04-06 CVE-2021-28205 Path Traversal vulnerability in Asus products
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter.
network
low complexity
asus CWE-22
4.9