Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-02-02 CVE-2021-21284 Path Traversal vulnerability in multiple products
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root.
low complexity
docker debian netapp CWE-22
6.8
2021-02-02 CVE-2020-4934 Path Traversal vulnerability in IBM Content Navigator 3.0.0
IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
4.3
2021-02-02 CVE-2021-3281 Path Traversal vulnerability in multiple products
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
network
low complexity
djangoproject fedoraproject netapp CWE-22
5.3
2021-02-01 CVE-2020-20290 Path Traversal vulnerability in Yccms 3.3
Directory traversal vulnerability in the yccms 3.3 project.
network
low complexity
yccms CWE-22
7.5
2021-01-29 CVE-2021-25129 Path Traversal vulnerability in HPE products
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice getvideodata_func function path traversal vulnerability.
local
low complexity
hpe CWE-22
7.8
2021-01-29 CVE-2021-25128 Path Traversal vulnerability in HPE products
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice gethelpdata_func function path traversal vulnerability.
local
low complexity
hpe CWE-22
7.8
2021-01-29 CVE-2021-25125 Path Traversal vulnerability in HPE products
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice delsolrecordedvideo_func function path traversal vulnerability.
local
low complexity
hpe CWE-22
7.8
2021-01-29 CVE-2021-25124 Path Traversal vulnerability in HPE products
The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice deletevideo_func function path traversal vulnerability.
local
low complexity
hpe CWE-22
7.8
2021-01-29 CVE-2021-3341 Path Traversal vulnerability in Dh2I Dxenterprise and Dxodyssey
A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5 through 20.x before 20.0.219.0, allows an attacker to read any file on the host file system via an HTTP request.
network
low complexity
dh2i CWE-22
7.5
2021-01-27 CVE-2020-4789 Path Traversal vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5