Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-02-23 CVE-2020-9354 Path Traversal vulnerability in Smartclient 12.0
An issue was discovered in SmartClient 12.0.
network
low complexity
smartclient CWE-22
7.5
2020-02-23 CVE-2020-9353 Path Traversal vulnerability in Smartclient 12.0
An issue was discovered in SmartClient 12.0.
network
low complexity
smartclient CWE-22
7.5
2020-02-20 CVE-2014-4650 Path Traversal vulnerability in multiple products
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
network
low complexity
python redhat CWE-22
critical
9.8
2020-02-20 CVE-2014-7951 Path Traversal vulnerability in Google Android 4.0.4
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a ..
low complexity
google CWE-22
4.6
2020-02-19 CVE-2014-9609 Path Traversal vulnerability in Netsweeper
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a ..
network
low complexity
netsweeper CWE-22
5.3
2020-02-17 CVE-2020-1853 Path Traversal vulnerability in Huawei Gaussdb 200 6.5.1
GaussDB 200 with version of 6.5.1 have a path traversal vulnerability.
network
low complexity
huawei CWE-22
6.5
2020-02-17 CVE-2020-9033 Path Traversal vulnerability in Microchip products
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
network
low complexity
microchip CWE-22
6.5
2020-02-17 CVE-2020-9032 Path Traversal vulnerability in Microchip products
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
network
low complexity
microchip CWE-22
6.5
2020-02-17 CVE-2020-9031 Path Traversal vulnerability in Microchip products
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.
network
low complexity
microchip CWE-22
6.5
2020-02-17 CVE-2020-9030 Path Traversal vulnerability in Microchip products
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
network
low complexity
microchip CWE-22
6.5