Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-07-15 CVE-2020-14507 Path Traversal vulnerability in Advantech Iview 5.6
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
network
low complexity
advantech CWE-22
critical
9.8
2020-07-14 CVE-2020-6286 Path Traversal vulnerability in SAP Netweaver Application Server Java
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
network
low complexity
sap CWE-22
5.3
2020-07-13 CVE-2020-15050 Path Traversal vulnerability in Supremainc Biostar 2
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2.
network
low complexity
supremainc CWE-22
7.5
2020-07-10 CVE-2020-8195 Path Traversal vulnerability in Citrix products
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
network
low complexity
citrix CWE-22
6.5
2020-07-09 CVE-2020-5366 Path Traversal vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability.
network
low complexity
dell CWE-22
6.5
2020-07-08 CVE-2020-5764 Path Traversal vulnerability in Mxplayer MX Player
MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode.
low complexity
mxplayer CWE-22
8.8
2020-07-07 CVE-2020-15583 Path Traversal vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
local
low complexity
google CWE-22
5.5
2020-07-02 CVE-2020-8161 Path Traversal vulnerability in multiple products
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
network
low complexity
rack-project debian canonical CWE-22
8.6
2020-07-01 CVE-2020-5902 Path Traversal vulnerability in F5 products
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
network
low complexity
f5 CWE-22
critical
9.8
2020-07-01 CVE-2020-13383 Path Traversal vulnerability in Os4Ed Opensis
openSIS through 7.4 allows Directory Traversal.
network
low complexity
os4ed CWE-22
7.5