Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-07-22 CVE-2020-15124 Path Traversal vulnerability in Intranda Goobi Viewer Core
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application.
network
low complexity
intranda CWE-22
6.5
2020-07-21 CVE-2016-7063 Path Traversal vulnerability in Pritunl Pritunl-Client
A flaw was found in pritunl-client before version 1.0.1116.6.
network
low complexity
pritunl CWE-22
critical
9.8
2020-07-21 CVE-2020-12499 Path Traversal vulnerability in Phoenixcontact Plcnext Engineer 202031
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
local
low complexity
phoenixcontact CWE-22
7.3
2020-07-20 CVE-2020-8214 Path Traversal vulnerability in Servey Project Servey 2.2.0
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
network
low complexity
servey-project CWE-22
7.5
2020-07-17 CVE-2020-9252 Path Traversal vulnerability in Huawei products
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability.
local
low complexity
huawei CWE-22
2.3
2020-07-17 CVE-2020-7684 Path Traversal vulnerability in Rollup-Plugin-Serve Project Rollup-Plugin-Serve
This affects all versions of package rollup-plugin-serve.
network
low complexity
rollup-plugin-serve-project CWE-22
critical
9.8
2020-07-16 CVE-2020-3401 Path Traversal vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system.
network
low complexity
cisco CWE-22
6.5
2020-07-16 CVE-2020-3381 Path Traversal vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system.
network
low complexity
cisco CWE-22
8.8
2020-07-15 CVE-2020-15779 Path Traversal vulnerability in Socket.Io-File Project Socket.Io-File
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js.
network
low complexity
socket-io-file-project CWE-22
7.5
2020-07-15 CVE-2020-11439 Path Traversal vulnerability in Librehealth EHR 2.0.0
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
network
low complexity
librehealth CWE-22
8.8