Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-08-03 CVE-2020-16116 Path Traversal vulnerability in multiple products
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
3.3
2020-07-31 CVE-2020-16136 Path Traversal vulnerability in Tgstation13 Tgstation-Server 4.4.0/4.4.1
In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory traversal ../ sequences in /Administration/Logs/ requests.
network
low complexity
tgstation13 CWE-22
7.7
2020-07-30 CVE-2020-8222 Path Traversal vulnerability in multiple products
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.
network
low complexity
pulsesecure ivanti CWE-22
6.8
2020-07-30 CVE-2020-8221 Path Traversal vulnerability in multiple products
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
network
low complexity
pulsesecure ivanti CWE-22
4.9
2020-07-29 CVE-2020-9689 Path Traversal vulnerability in Magento
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability.
local
low complexity
magento CWE-22
6.5
2020-07-29 CVE-2020-14490 Path Traversal vulnerability in Openclinic GA Project Openclinic GA 5.09.02/5.89.05B
OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.
network
low complexity
openclinic-ga-project CWE-22
8.8
2020-07-29 CVE-2020-5614 Path Traversal vulnerability in Kujirahand Konawiki
Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
kujirahand CWE-22
5.3
2020-07-28 CVE-2020-5377 Path Traversal vulnerability in Dell EMC Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
network
low complexity
dell CWE-22
critical
9.1
2020-07-28 CVE-2020-15712 Path Traversal vulnerability in Rconfig 3.9.5
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system.
network
low complexity
rconfig CWE-22
4.3
2020-07-27 CVE-2020-15592 Path Traversal vulnerability in Riverbed Steelcentral Aternity Agent
SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file.
network
low complexity
riverbed CWE-22
7.5