Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-11-12 CVE-2019-18924 Path Traversal vulnerability in Systematic Iris Webforms 5.4
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal.
network
low complexity
systematic CWE-22
5.3
2019-11-08 CVE-2019-17327 Path Traversal vulnerability in Tmaxsoft Jeus 7/8
JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input parameter check when uploading installation file in administration web page.
network
low complexity
tmaxsoft CWE-22
7.2
2019-11-07 CVE-2019-16876 Path Traversal vulnerability in Portainer
Portainer before 1.22.1 allows Directory Traversal.
network
low complexity
portainer CWE-22
7.5
2019-11-07 CVE-2019-15004 Path Traversal vulnerability in Atlassian Jira Service Desk
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability.
network
low complexity
atlassian CWE-22
7.5
2019-11-07 CVE-2019-15003 Path Traversal vulnerability in Atlassian Jira Service Desk
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via authorization bypass.
network
low complexity
atlassian CWE-22
5.3
2019-11-06 CVE-2014-9014 Path Traversal vulnerability in Wpmarketplace Project Wpmarketplace 2.4.0
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a ..
network
low complexity
wpmarketplace-project CWE-22
4.3
2019-11-06 CVE-2019-10218 Path Traversal vulnerability in multiple products
A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators.
network
low complexity
samba fedoraproject CWE-22
6.5
2019-11-02 CVE-2019-18665 Path Traversal vulnerability in Secudos Domos
The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.
network
low complexity
secudos CWE-22
7.5
2019-10-31 CVE-2019-13551 Path Traversal vulnerability in Advantech Wise-Paas/Rmm 3.3.29
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior.
network
low complexity
advantech CWE-22
critical
9.8
2019-10-30 CVE-2019-17324 Path Traversal vulnerability in Clipsoft Rexpert 1.0.0.527
ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters.
network
low complexity
clipsoft CWE-22
6.5