Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-05-09 CVE-2020-12764 Path Traversal vulnerability in Solis Gnuteca 3.8
Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.
network
low complexity
solis CWE-22
5.3
2020-05-08 CVE-2020-11531 Path Traversal vulnerability in Zohocorp products
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request.
network
low complexity
zohocorp CWE-22
8.8
2020-05-08 CVE-2020-12737 Path Traversal vulnerability in Maxum Rumpus
An issue was discovered in Maxum Rumpus before 8.2.12 on macOS.
network
low complexity
maxum CWE-22
6.5
2020-05-08 CVE-2020-12026 Path Traversal vulnerability in Advantech Webaccess
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
network
low complexity
advantech CWE-22
8.8
2020-05-08 CVE-2020-12010 Path Traversal vulnerability in Advantech Webaccess
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
local
low complexity
advantech CWE-22
7.1
2020-05-08 CVE-2020-12006 Path Traversal vulnerability in Advantech Webaccess
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
network
low complexity
advantech CWE-22
critical
9.8
2020-05-07 CVE-2020-10794 Path Traversal vulnerability in Gira Tks-Ip-Gateway Firmware 4.0.7.7
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database.
network
low complexity
gira CWE-22
critical
9.8
2020-05-07 CVE-2020-4430 Path Traversal vulnerability in IBM Data Risk Manager
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
4.3
2020-05-07 CVE-2020-12116 Path Traversal vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
network
low complexity
zohocorp CWE-22
7.5
2020-05-07 CVE-2020-5744 Path Traversal vulnerability in Tecnick Tcexam 14.2.2
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
network
low complexity
tecnick CWE-22
4.9