Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-05-08 CVE-2020-12006 Path Traversal vulnerability in Advantech Webaccess
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
network
low complexity
advantech CWE-22
critical
9.8
2020-05-07 CVE-2020-10794 Path Traversal vulnerability in Gira Tks-Ip-Gateway Firmware 4.0.7.7
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database.
network
low complexity
gira CWE-22
critical
9.8
2020-05-07 CVE-2020-4430 Path Traversal vulnerability in IBM Data Risk Manager
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
4.3
2020-05-07 CVE-2020-12116 Path Traversal vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
network
low complexity
zohocorp CWE-22
7.5
2020-05-07 CVE-2020-5744 Path Traversal vulnerability in Tecnick Tcexam 14.2.2
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
network
low complexity
tecnick CWE-22
4.9
2020-05-07 CVE-2020-12448 Path Traversal vulnerability in Gitlab
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
network
low complexity
gitlab CWE-22
5.3
2020-05-07 CVE-2020-11431 Path Traversal vulnerability in Inetsoftware Clear Reports, Helpdesk and Pdfc
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
network
low complexity
inetsoftware CWE-22
critical
9.1
2020-05-07 CVE-2020-8983 Path Traversal vulnerability in Citrix Sharefile Storagezones Controller
An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution.
network
low complexity
citrix CWE-22
7.5
2020-05-07 CVE-2020-8982 Path Traversal vulnerability in Citrix Sharefile Storagezones Controller
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020.
network
low complexity
citrix CWE-22
7.5
2020-05-07 CVE-2020-7473 Path Traversal vulnerability in Citrix Sharefile Storagezones Controller
In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users.
network
low complexity
citrix CWE-22
7.5