Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-01-27 CVE-2021-25311 Path Traversal vulnerability in Wisc Htcondor
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.
network
low complexity
wisc CWE-22
critical
9.9
2021-01-26 CVE-2021-3223 Path Traversal vulnerability in Nodered Node-Red-Dashboard
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
network
low complexity
nodered CWE-22
7.5
2021-01-26 CVE-2021-3199 Path Traversal vulnerability in Onlyoffice Document Server
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..
network
low complexity
onlyoffice CWE-22
critical
9.8
2021-01-26 CVE-2021-3152 Path Traversal vulnerability in Home-Assistant
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations.
network
low complexity
home-assistant CWE-22
5.3
2021-01-26 CVE-2021-25864 Path Traversal vulnerability in Dgtl Huemagic 3.0.0
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
network
low complexity
dgtl CWE-22
7.5
2021-01-26 CVE-2020-23161 Path Traversal vulnerability in Pyres Termod4 Firmware
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.
network
low complexity
pyres CWE-22
6.5
2021-01-21 CVE-2020-8570 Path Traversal vulnerability in Kubernetes Java
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive.
network
low complexity
kubernetes CWE-22
critical
9.1
2021-01-21 CVE-2020-8568 Path Traversal vulnerability in Kubernetes Secrets Store CSI Driver 0.0.15/0.0.16
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets.
network
low complexity
kubernetes CWE-22
6.5
2021-01-21 CVE-2020-8567 Path Traversal vulnerability in multiple products
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
network
low complexity
google hashicorp microsoft CWE-22
6.5
2021-01-20 CVE-2021-1357 Path Traversal vulnerability in Cisco products
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system.
network
low complexity
cisco CWE-22
6.5