Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-11-27 CVE-2019-19877 Path Traversal vulnerability in Br-Automation Industrial Automation Aprol
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08.
network
low complexity
br-automation CWE-22
5.3
2020-11-26 CVE-2020-13886 Path Traversal vulnerability in Intelbras products
Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.
network
low complexity
intelbras CWE-22
5.3
2020-11-24 CVE-2020-4000 Path Traversal vulnerability in VMWare Sd-Wan Orchestrator
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal.
network
low complexity
vmware CWE-22
8.8
2020-11-24 CVE-2020-28348 Path Traversal vulnerability in Hashicorp Nomad
HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type.
network
low complexity
hashicorp CWE-22
6.5
2020-11-24 CVE-2020-15929 Path Traversal vulnerability in Ortussolutions Testbox
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
network
low complexity
ortussolutions CWE-22
critical
9.8
2020-11-24 CVE-2020-15928 Path Traversal vulnerability in Ortussolutions Testbox
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
network
low complexity
ortussolutions CWE-22
5.3
2020-11-23 CVE-2020-15246 Path Traversal vulnerability in Octobercms October
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework.
network
low complexity
octobercms CWE-22
7.5
2020-11-19 CVE-2020-13355 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14.
network
low complexity
gitlab CWE-22
8.1
2020-11-18 CVE-2020-28574 Path Traversal vulnerability in Trendmicro Worry-Free Business Security 10.0
A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.
network
low complexity
trendmicro CWE-22
7.5
2020-11-18 CVE-2020-26078 Path Traversal vulnerability in Cisco IOT Field Network Director
A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system.
network
low complexity
cisco CWE-22
6.5