Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-04-29 CVE-2019-19102 Path Traversal vulnerability in Br-Automation Automation Studio
A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories.
network
low complexity
br-automation CWE-22
7.5
2020-04-29 CVE-2020-12443 Path Traversal vulnerability in Bigbluebutton
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence.
network
low complexity
bigbluebutton CWE-22
critical
9.8
2020-04-28 CVE-2020-12103 Path Traversal vulnerability in Tiny File Manager Project Tiny File Manager 2.4.1
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
network
low complexity
tiny-file-manager-project CWE-22
7.7
2020-04-28 CVE-2020-12102 Path Traversal vulnerability in Tiny File Manager Project Tiny File Manager 2.4.1
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality.
network
low complexity
tiny-file-manager-project CWE-22
7.7
2020-04-27 CVE-2020-11420 Path Traversal vulnerability in multiple products
UPS Adapter CS141 before 1.90 allows Directory Traversal.
network
low complexity
abb generex CWE-22
6.5
2020-04-24 CVE-2020-6828 Path Traversal vulnerability in Mozilla Firefox ESR
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory.
network
low complexity
mozilla CWE-22
7.5
2020-04-24 CVE-2020-12128 Path Traversal vulnerability in File Transfer Ifamily Project File Transfer Ifamily 2.1
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
network
low complexity
file-transfer-ifamily-project CWE-22
7.5
2020-04-23 CVE-2020-12112 Path Traversal vulnerability in Bigbluebutton
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
network
low complexity
bigbluebutton CWE-22
7.5
2020-04-21 CVE-2020-1699 Path Traversal vulnerability in multiple products
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0.
network
low complexity
linuxfoundation redhat CWE-22
7.5
2020-04-20 CVE-2017-18824 Path Traversal vulnerability in Netgear products
Certain NETGEAR devices are affected by directory traversal.
local
low complexity
netgear CWE-22
3.3