Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2020-04-30 CVE-2020-11652 Path Traversal vulnerability in multiple products
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
6.5
2020-04-30 CVE-2020-10691 Path Traversal vulnerability in Redhat Ansible Engine and Ansible Tower
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install.
local
low complexity
redhat CWE-22
5.2
2020-04-29 CVE-2020-12479 Path Traversal vulnerability in Teampass 2.1.27.36
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.
network
low complexity
teampass CWE-22
8.8
2020-04-29 CVE-2020-12251 Path Traversal vulnerability in Gigamon Gigavue
An issue was discovered in Gigamon GigaVUE 5.5.01.11.
network
high complexity
gigamon CWE-22
2.2
2020-04-29 CVE-2020-12447 Path Traversal vulnerability in Onkyo Tx-Nr585 Firmware 1000000000000080000
A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.
network
low complexity
onkyo CWE-22
7.5
2020-04-29 CVE-2019-19102 Path Traversal vulnerability in Br-Automation Automation Studio
A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x and 4.2.x allow unauthenticated users to write to certain local directories.
network
low complexity
br-automation CWE-22
7.5
2020-04-29 CVE-2020-12443 Path Traversal vulnerability in Bigbluebutton
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence.
network
low complexity
bigbluebutton CWE-22
critical
9.8
2020-04-28 CVE-2020-12103 Path Traversal vulnerability in Tiny File Manager Project Tiny File Manager 2.4.1
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
network
low complexity
tiny-file-manager-project CWE-22
7.7
2020-04-28 CVE-2020-12102 Path Traversal vulnerability in Tiny File Manager Project Tiny File Manager 2.4.1
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality.
network
low complexity
tiny-file-manager-project CWE-22
7.7
2020-04-27 CVE-2020-11420 Path Traversal vulnerability in multiple products
UPS Adapter CS141 before 1.90 allows Directory Traversal.
network
low complexity
abb generex CWE-22
6.5