Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-13635 Path Traversal vulnerability in Wpfastestcache WP Fastest Cache
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
network
low complexity
wpfastestcache CWE-22
critical
9.1
2019-07-29 CVE-2019-14418 Path Traversal vulnerability in Veritas Resiliency Platform
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1.
network
low complexity
veritas CWE-22
8.8
2019-07-29 CVE-2019-6726 Path Traversal vulnerability in Wpfastestcache WP Fastest Cache
The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ../ in an HTTP Referer header.
network
high complexity
wpfastestcache CWE-22
6.5
2019-07-29 CVE-2019-1020001 Path Traversal vulnerability in Yardoc Yard
yard before 0.9.20 allows path traversal.
network
low complexity
yardoc CWE-22
7.5
2019-07-28 CVE-2019-14362 Path Traversal vulnerability in Openbravo ERP 3.0
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal.
network
low complexity
openbravo CWE-22
5.4
2019-07-28 CVE-2019-14322 Path Traversal vulnerability in Palletsprojects Werkzeug
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
network
low complexity
palletsprojects CWE-22
7.5
2019-07-26 CVE-2019-10265 Path Traversal vulnerability in Ahsay Cloud Backup Suite
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50.
network
low complexity
ahsay CWE-22
7.5
2019-07-26 CVE-2019-13385 Path Traversal vulnerability in Control-Webpanel Webpanel 0.9.8.840
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allows attackers to enumerate users and check for active users of the application by reading /tmp/login.log.
network
low complexity
control-webpanel CWE-22
4.3
2019-07-23 CVE-2019-1010205 Path Traversal vulnerability in Linagora Hublin
LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal.
network
low complexity
linagora CWE-22
7.5
2019-07-23 CVE-2019-14240 Path Traversal vulnerability in Wcms 0.3.2
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.
network
low complexity
wcms CWE-22
8.1