Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2020-0539 Path Traversal vulnerability in Intel products
Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-22
5.5
2020-06-10 CVE-2020-11798 Path Traversal vulnerability in Mitel Micollab Audio, web & Video Conferencing
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation.
network
low complexity
mitel CWE-22
5.3
2020-06-08 CVE-2020-6110 Path Traversal vulnerability in Zoom 4.6.10
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets.
network
low complexity
zoom CWE-22
8.8
2020-06-08 CVE-2020-6109 Path Traversal vulnerability in Zoom 4.6.10
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs.
network
low complexity
zoom CWE-22
critical
9.8
2020-06-04 CVE-2020-12851 Path Traversal vulnerability in Pydio Cells 2.0.4
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application.
network
low complexity
pydio CWE-22
8.1
2020-06-04 CVE-2020-13836 Path Traversal vulnerability in Google Android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.
network
low complexity
google CWE-22
7.5
2020-06-04 CVE-2019-16384 Path Traversal vulnerability in Cybelesoft Thinfinity Virtualui
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration.
network
low complexity
cybelesoft CWE-22
6.5
2020-06-04 CVE-2020-13818 Path Traversal vulnerability in Zohocorp Manageengine Opmanager
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
network
low complexity
zohocorp CWE-22
7.5
2020-06-03 CVE-2020-13795 Path Traversal vulnerability in Naviwebs Navigate CMS
An issue was discovered in Navigate CMS through 2.8.7.
network
low complexity
naviwebs CWE-22
5.3
2020-06-03 CVE-2020-13792 Path Traversal vulnerability in Playtube 1.8
PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.
network
low complexity
playtube CWE-22
4.3