Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2020-3401 Path Traversal vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system.
network
low complexity
cisco CWE-22
6.5
2020-07-16 CVE-2020-3381 Path Traversal vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system.
network
low complexity
cisco CWE-22
8.8
2020-07-15 CVE-2020-15779 Path Traversal vulnerability in Socket.Io-File Project Socket.Io-File
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js.
network
low complexity
socket-io-file-project CWE-22
7.5
2020-07-15 CVE-2020-11439 Path Traversal vulnerability in Librehealth EHR 2.0.0
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
network
low complexity
librehealth CWE-22
8.8
2020-07-15 CVE-2020-14507 Path Traversal vulnerability in Advantech Iview 5.6
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
network
low complexity
advantech CWE-22
critical
9.8
2020-07-14 CVE-2020-6286 Path Traversal vulnerability in SAP Netweaver Application Server Java
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
network
low complexity
sap CWE-22
5.3
2020-07-13 CVE-2020-15050 Path Traversal vulnerability in Supremainc Biostar 2
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2.
network
low complexity
supremainc CWE-22
7.5
2020-07-10 CVE-2020-8195 Path Traversal vulnerability in Citrix products
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
network
low complexity
citrix CWE-22
6.5
2020-07-09 CVE-2020-5366 Path Traversal vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability.
network
low complexity
dell CWE-22
6.5
2020-07-08 CVE-2020-5764 Path Traversal vulnerability in Mxplayer MX Player
MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode.
low complexity
mxplayer CWE-22
8.8