Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-05-20 CVE-2020-21055 Path Traversal vulnerability in Fusionpbx 4.5.7
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
network
low complexity
fusionpbx CWE-22
6.5
2021-05-20 CVE-2020-21056 Path Traversal vulnerability in Fusionpbx 4.5.7
Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.
network
low complexity
fusionpbx CWE-22
4.3
2021-05-20 CVE-2020-21057 Path Traversal vulnerability in Fusionpbx 4.5.7
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.
network
low complexity
fusionpbx CWE-22
8.1
2021-05-20 CVE-2020-35580 Path Traversal vulnerability in Searchblox
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request.
network
low complexity
searchblox CWE-22
7.5
2021-05-20 CVE-2021-3426 Path Traversal vulnerability in multiple products
There's a flaw in Python 3's pydoc.
5.7
2021-05-19 CVE-2020-36364 Path Traversal vulnerability in Smartstore Smartstorenet
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0.
network
low complexity
smartstore CWE-22
critical
9.1
2021-05-18 CVE-2020-18178 Path Traversal vulnerability in Hongcms Project Hongcms 4.0.0
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
network
low complexity
hongcms-project CWE-22
critical
9.8
2021-05-12 CVE-2021-32572 Path Traversal vulnerability in Specotech web Viewer
Speco Web Viewer through 2021-05-12 allows Directory Traversal via GET request for a URI with /..
network
low complexity
specotech CWE-22
7.5
2021-05-10 CVE-2020-23575 Path Traversal vulnerability in Kyocera D-Copia253Mf Plus Firmware
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus.
network
low complexity
kyocera CWE-22
7.5
2021-05-06 CVE-2021-28149 Path Traversal vulnerability in Hongdian H8922 Firmware 3.0.5
Hongdian H8922 3.0.5 devices allow Directory Traversal.
network
low complexity
hongdian CWE-22
6.5