Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-07-17 CVE-2024-28992 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability.
network
low complexity
solarwinds CWE-22
critical
9.4
2024-07-17 CVE-2024-40617 Path Traversal vulnerability in Fujitsu Network Edgiot Gw1500 Firmware
Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS).
network
low complexity
fujitsu CWE-22
6.5
2024-07-16 CVE-2024-39036 Path Traversal vulnerability in Seacms 12.9
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
network
low complexity
seacms CWE-22
6.5
2024-07-15 CVE-2024-6746 Path Traversal vulnerability in Easyspider 0.6.2
A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows.
low complexity
easyspider CWE-22
8.8
2024-07-12 CVE-2024-31947 Path Traversal vulnerability in Stonefly Storage Concentrator
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users.
network
low complexity
stonefly CWE-22
6.5
2024-07-09 CVE-2024-22377 Path Traversal vulnerability in Pingidentity Pingfederate
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
network
low complexity
pingidentity CWE-22
5.3
2024-07-09 CVE-2024-39171 Path Traversal vulnerability in PHPvibe
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
network
low complexity
phpvibe CWE-22
critical
9.8
2024-07-09 CVE-2024-37437 Path Traversal vulnerability in Elementor Website Builder
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n/a through 3.22.1.
network
low complexity
elementor CWE-22
5.4
2024-07-04 CVE-2024-39937 Path Traversal vulnerability in Supos 5.0
supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.
network
low complexity
supos CWE-22
7.5
2024-07-02 CVE-2024-5865 Path Traversal vulnerability in Delinea Privileged Access Service
Vulnerability in Delinea Centrify PAS v.
network
low complexity
delinea CWE-22
6.5