Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-33182 Path Traversal vulnerability in Synology Diskstation Manager
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors.
network
low complexity
synology CWE-22
4.3
2021-05-27 CVE-2021-32643 Path Traversal vulnerability in Typelevel Http4S
Http4s is a Scala interface for HTTP services.
network
low complexity
typelevel CWE-22
5.8
2021-05-25 CVE-2021-29695 Path Traversal vulnerability in IBM products
IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5
2021-05-24 CVE-2020-20907 Path Traversal vulnerability in Metinfo 7.0.0
MetInfo 7.0 beta is affected by a file modification vulnerability.
network
low complexity
metinfo CWE-22
critical
9.1
2021-05-24 CVE-2021-21001 Path Traversal vulnerability in Wago products
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
network
low complexity
wago CWE-22
6.5
2021-05-24 CVE-2021-33497 Path Traversal vulnerability in Dutchcoders Transfer.Sh
Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.
network
low complexity
dutchcoders CWE-22
critical
9.1
2021-05-21 CVE-2020-23766 Path Traversal vulnerability in Htmly 2.7.5
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
network
low complexity
htmly CWE-22
6.5
2021-05-21 CVE-2021-32633 Path Traversal vulnerability in multiple products
Zope is an open-source web application server.
network
low complexity
plone zope CWE-22
8.8
2021-05-21 CVE-2021-28798 Path Traversal vulnerability in Qnap QTS and Quts Hero
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero.
network
low complexity
qnap CWE-22
7.5
2021-05-20 CVE-2020-21055 Path Traversal vulnerability in Fusionpbx 4.5.7
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.
network
low complexity
fusionpbx CWE-22
6.5