Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-05-05 CVE-2020-12649 Path Traversal vulnerability in Gurbalib Project Gurbalib 20200430
Gurbalib through 2020-04-30 allows lib/cmds/player/help.c directory traversal for reading administrative paths.
network
low complexity
gurbalib-project CWE-22
7.5
2020-05-04 CVE-2020-12640 Path Traversal vulnerability in multiple products
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
network
low complexity
roundcube opensuse CWE-22
critical
9.8
2020-05-04 CVE-2020-4209 Path Traversal vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
5.4
2020-05-04 CVE-2020-12475 Path Traversal vulnerability in Tp-Link Omada Controller 3.2.6
TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar.
local
low complexity
tp-link CWE-22
5.5
2020-05-04 CVE-2020-1631 Path Traversal vulnerability in Juniper Junos
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal.
network
low complexity
juniper CWE-22
critical
9.8
2020-04-30 CVE-2020-11652 Path Traversal vulnerability in multiple products
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
6.5
2020-04-30 CVE-2020-10691 Path Traversal vulnerability in Redhat Ansible Engine and Ansible Tower
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install.
local
low complexity
redhat CWE-22
5.2
2020-04-29 CVE-2020-12479 Path Traversal vulnerability in Teampass 2.1.27.36
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.
network
low complexity
teampass CWE-22
8.8
2020-04-29 CVE-2020-12251 Path Traversal vulnerability in Gigamon Gigavue
An issue was discovered in Gigamon GigaVUE 5.5.01.11.
network
high complexity
gigamon CWE-22
2.2
2020-04-29 CVE-2020-12447 Path Traversal vulnerability in Onkyo Tx-Nr585 Firmware 1000000000000080000
A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.
network
low complexity
onkyo CWE-22
7.5