Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-16867 Path Traversal vulnerability in Hongcms Project Hongcms 3.0.0
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774.
network
low complexity
hongcms-project CWE-22
6.5
2019-09-23 CVE-2019-13063 Path Traversal vulnerability in Sahipro Sahi PRO 8.0.0
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page.
network
low complexity
sahipro CWE-22
7.5
2019-09-21 CVE-2019-16680 Path Traversal vulnerability in multiple products
An issue was discovered in GNOME file-roller before 3.29.91.
network
low complexity
gnome redhat debian canonical CWE-22
4.3
2019-09-21 CVE-2019-16679 Path Traversal vulnerability in Gilacms Gila CMS
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
network
low complexity
gilacms CWE-22
4.9
2019-09-20 CVE-2015-9406 Path Traversal vulnerability in Mtheme-Unus Project Mtheme-Unus
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a ..
network
low complexity
mtheme-unus-project CWE-22
7.5
2019-09-20 CVE-2014-10397 Path Traversal vulnerability in Para Antioch 20140907
The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.
network
low complexity
para CWE-22
7.5
2019-09-20 CVE-2014-10396 Path Traversal vulnerability in Organizedthemes Epic
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
network
low complexity
organizedthemes CWE-22
7.5
2019-09-20 CVE-2019-11327 Path Traversal vulnerability in Topcon Net-G5 Firmware 5.2.2
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2.
network
low complexity
topcon CWE-22
4.9
2019-09-20 CVE-2019-14914 Path Traversal vulnerability in Prise Adas 1.7.0
An issue was discovered in PRiSE adAS 1.7.0.
network
low complexity
prise CWE-22
critical
9.1
2019-09-19 CVE-2019-16511 Path Traversal vulnerability in Firegiant WIX Toolset
An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2.
local
low complexity
firegiant CWE-22
5.5