Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-10-19 CVE-2021-41150 Path Traversal vulnerability in Amazon Tough
Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories.
network
low complexity
amazon CWE-22
6.5
2021-10-19 CVE-2021-42261 Path Traversal vulnerability in Revisorlab Video Management System
Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability.
network
low complexity
revisorlab CWE-22
7.5
2021-10-18 CVE-2021-41151 Path Traversal vulnerability in Linuxfoundation Backstage
Backstage is an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-22
4.9
2021-10-18 CVE-2021-41152 Path Traversal vulnerability in Frentix Openolat
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system.
network
low complexity
frentix CWE-22
7.7
2021-10-15 CVE-2021-40724 Path Traversal vulnerability in Adobe Acrobat Reader
Acrobat Reader for Android versions 21.8.0 (and earlier) are affected by a Path traversal vulnerability.
local
low complexity
adobe CWE-22
7.8
2021-10-15 CVE-2021-3874 Path Traversal vulnerability in Bookstackapp Bookstack
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
network
low complexity
bookstackapp CWE-22
6.5
2021-10-15 CVE-2021-40988 Path Traversal vulnerability in Arubanetworks Clearpass Policy Manager
A remote directory traversal vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1.
network
low complexity
arubanetworks CWE-22
7.2
2021-10-14 CVE-2021-33178 Path Traversal vulnerability in Nagvis
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability.
network
low complexity
nagvis CWE-22
6.5
2021-10-13 CVE-2021-20123 Path Traversal vulnerability in Draytek Vigorconnect 1.6.0
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint.
network
low complexity
draytek CWE-22
7.5
2021-10-13 CVE-2021-20124 Path Traversal vulnerability in Draytek Vigorconnect 1.6.0
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint.
network
low complexity
draytek CWE-22
7.5