Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-06-22 CVE-2020-14461 Path Traversal vulnerability in Zyxel Wap6806 Firmware 1.00(Abal.6)C0
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
network
low complexity
zyxel CWE-22
8.6
2020-06-19 CVE-2017-18912 Path Traversal vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.
network
low complexity
mattermost CWE-22
critical
9.8
2020-06-19 CVE-2017-18874 Path Traversal vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used.
network
low complexity
mattermost CWE-22
6.5
2020-06-19 CVE-2019-20851 Path Traversal vulnerability in Mattermost
An issue was discovered in Mattermost Mobile Apps before 1.26.0.
network
low complexity
mattermost CWE-22
critical
9.1
2020-06-19 CVE-2020-14452 Path Traversal vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 5.21.0.
network
low complexity
mattermost CWE-22
5.3
2020-06-19 CVE-2020-5590 Path Traversal vulnerability in Ec-Cube
Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.
network
low complexity
ec-cube CWE-22
8.1
2020-06-18 CVE-2020-3241 Path Traversal vulnerability in Cisco UCS Director
A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device.
network
low complexity
cisco CWE-22
6.5
2020-06-18 CVE-2020-3236 Path Traversal vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files.
local
low complexity
cisco CWE-22
6.7
2020-06-17 CVE-2020-12827 Path Traversal vulnerability in Mjml
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
network
low complexity
mjml CWE-22
7.2
2020-06-16 CVE-2020-7497 Path Traversal vulnerability in Schneider-Electric Ecostruxure Operator Terminal Expert 3.0/3.1
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.
network
low complexity
schneider-electric CWE-22
critical
9.8