Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-11-02 CVE-2020-18438 Path Traversal vulnerability in PHPok 5.1
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.
network
low complexity
phpok CWE-22
7.5
2021-11-01 CVE-2021-29212 Path Traversal vulnerability in HP ILO Amplifier Pack
A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95.
network
low complexity
hp CWE-22
critical
9.8
2021-10-29 CVE-2020-25872 Path Traversal vulnerability in Frogcms Project Frogcms 0.9.5
A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter.
network
low complexity
frogcms-project CWE-22
4.9
2021-10-29 CVE-2020-25873 Path Traversal vulnerability in Baijiacms Project Baijiacms 4
A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily delete folders on the server via the "id" parameter.
network
low complexity
baijiacms-project CWE-22
6.5
2021-10-29 CVE-2020-25881 Path Traversal vulnerability in Ranko Rkcms
A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=../../../../111.txt&filetype=image/jpeg of the master version of RKCMS.
local
low complexity
ranko CWE-22
5.5
2021-10-28 CVE-2021-3823 Path Traversal vulnerability in Bitdefender Gravityzone
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances.
network
low complexity
bitdefender CWE-22
critical
9.8
2021-10-28 CVE-2021-22404 Path Traversal vulnerability in Huawei Emui and Magic UI
There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-22
5.3
2021-10-27 CVE-2021-34762 Path Traversal vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device.
network
low complexity
cisco CWE-22
8.1
2021-10-27 CVE-2021-37124 Path Traversal vulnerability in Huawei PC Smart Full Scene and Pcmanager
There is a path traversal vulnerability in Huawei PC product.
low complexity
huawei CWE-22
6.5
2021-10-27 CVE-2021-37130 Path Traversal vulnerability in Huawei Fusioncube Firmware 6.0.2
There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname.
network
low complexity
huawei CWE-22
7.5