Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-07-16 CVE-2024-5852 Path Traversal vulnerability in Iptanus Wordpress File Upload
The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode.
network
low complexity
iptanus CWE-22
4.3
2024-07-15 CVE-2024-6746 Path Traversal vulnerability in Easyspider 0.6.2
A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows.
low complexity
easyspider CWE-22
8.8
2024-07-15 CVE-2024-39741 Path Traversal vulnerability in IBM Datacap and Datacap Navigator
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
5.3
2024-07-12 CVE-2024-31947 Path Traversal vulnerability in Stonefly Storage Concentrator
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users.
network
low complexity
stonefly CWE-22
6.5
2024-07-11 CVE-2024-2602 Path Traversal vulnerability in Schneider-Electric Foxrtu Station
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
local
low complexity
schneider-electric CWE-22
7.8
2024-07-09 CVE-2024-22377 Path Traversal vulnerability in Pingidentity Pingfederate
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
network
low complexity
pingidentity CWE-22
5.3
2024-07-09 CVE-2024-39171 Path Traversal vulnerability in PHPvibe
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
network
low complexity
phpvibe CWE-22
critical
9.8
2024-07-09 CVE-2024-37513 Path Traversal vulnerability in Themewinter Wpcafe
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue affects WPCafe: from n/a through 2.2.27.
network
low complexity
themewinter CWE-22
8.8
2024-07-09 CVE-2024-37520 Path Traversal vulnerability in Radiustheme Shopbuilder
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons allows Path Traversal.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 2.1.12.
network
low complexity
radiustheme CWE-22
8.8
2024-07-09 CVE-2024-37410 Path Traversal vulnerability in Wpbeaveraddons Powerpack Lite for Beaver Builder
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Path Traversal.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.3.
network
low complexity
wpbeaveraddons CWE-22
7.2