Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-12-12 CVE-2019-16246 Path Traversal vulnerability in Intesync Solismed 3.3
Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931.
network
low complexity
intesync CWE-22
critical
9.8
2019-12-12 CVE-2019-15931 Path Traversal vulnerability in Intesync Solismed 3.3
Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
network
low complexity
intesync CWE-22
critical
9.8
2019-12-11 CVE-2019-19374 Path Traversal vulnerability in Squiz Matrix
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during interaction with the File Upload field type, when a custom form exists.
network
low complexity
squiz CWE-22
critical
9.1
2019-12-09 CVE-2019-19683 Path Traversal vulnerability in Nopcommerce 4.20
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.
network
low complexity
nopcommerce CWE-22
critical
9.1
2019-12-09 CVE-2019-14251 Path Traversal vulnerability in Temenos T24 R15.01
An issue was discovered in T24 in TEMENOS Channels R15.01.
network
low complexity
temenos CWE-22
7.5
2019-12-05 CVE-2019-7195 Path Traversal vulnerability in Qnap Photo Station
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
network
low complexity
qnap CWE-22
critical
9.8
2019-12-05 CVE-2019-7194 Path Traversal vulnerability in Qnap Photo Station
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
network
low complexity
qnap CWE-22
critical
9.8
2019-12-04 CVE-2019-19229 Path Traversal vulnerability in Fronius products
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
network
low complexity
fronius CWE-22
6.5
2019-12-03 CVE-2019-19459 Path Traversal vulnerability in Saltosystem Proaccess Space 5.4.3.0/5.5
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0.
network
low complexity
saltosystem CWE-22
critical
9.8
2019-12-03 CVE-2019-19458 Path Traversal vulnerability in Saltosystem Proaccess Space 5.4.3.0/5.5
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
network
low complexity
saltosystem CWE-22
8.6