Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-06-22 CVE-2020-14946 Path Traversal vulnerability in Globalradar BSA Radar 1.6.7234.24750
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files.
network
low complexity
globalradar CWE-22
4.3
2020-06-22 CVE-2020-13158 Path Traversal vulnerability in Articatech Artica Proxy 4.28.030.418/4.28.030418
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
network
low complexity
articatech CWE-22
7.5
2020-06-22 CVE-2020-14461 Path Traversal vulnerability in Zyxel Wap6806 Firmware 1.00(Abal.6)C0
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
network
low complexity
zyxel CWE-22
8.6
2020-06-19 CVE-2017-18912 Path Traversal vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.
network
low complexity
mattermost CWE-22
critical
9.8
2020-06-19 CVE-2017-18874 Path Traversal vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used.
network
low complexity
mattermost CWE-22
6.5
2020-06-19 CVE-2019-20851 Path Traversal vulnerability in Mattermost
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
network
low complexity
mattermost CWE-22
critical
9.1
2020-06-19 CVE-2020-14452 Path Traversal vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.21.0.
network
low complexity
mattermost CWE-22
5.3
2020-06-19 CVE-2020-5590 Path Traversal vulnerability in Ec-Cube
Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
network
low complexity
ec-cube CWE-22
8.1
2020-06-18 CVE-2020-3241 Path Traversal vulnerability in Cisco UCS Director
A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device.
network
low complexity
cisco CWE-22
6.5
2020-06-18 CVE-2020-3236 Path Traversal vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files.
local
low complexity
cisco CWE-22
6.7