Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-11-20 CVE-2019-10765 Path Traversal vulnerability in Iobroker Iobroker.Admin
iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.
network
low complexity
iobroker CWE-22
critical
9.8
2019-11-18 CVE-2019-3423 Path Traversal vulnerability in Ztehome C520V21 Firmware 2.1.14
permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices.
network
low complexity
ztehome CWE-22
5.3
2019-11-14 CVE-2019-18978 Path Traversal vulnerability in multiple products
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby.
network
low complexity
rack-cors-project debian canonical CWE-22
5.3
2019-11-14 CVE-2013-3073 Path Traversal vulnerability in Netgear Wndr4700 Firmware 1.0.0.34
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
network
low complexity
netgear CWE-22
critical
9.8
2019-11-14 CVE-2019-3662 Path Traversal vulnerability in Mcafee Advanced Threat Defense
Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.
network
low complexity
mcafee CWE-22
6.5
2019-11-13 CVE-2019-18951 Path Traversal vulnerability in Sibsoft Xfilesharing 2.5.1
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
network
low complexity
sibsoft CWE-22
7.5
2019-11-13 CVE-2013-4657 Path Traversal vulnerability in Netgear Wnr3500L Firmware and Wnr3500U Firmware
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
network
low complexity
netgear CWE-22
critical
9.8
2019-11-13 CVE-2013-4654 Path Traversal vulnerability in Tp-Link Tl-1043Nd Firmware and Tl-Wdr4300 Firmware
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
network
low complexity
tp-link CWE-22
critical
9.8
2019-11-13 CVE-2013-4656 Path Traversal vulnerability in Asus Rt-Ac66U Firmware and Rt-N56U Firmware
Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.
network
low complexity
asus CWE-22
critical
9.8
2019-11-12 CVE-2019-18924 Path Traversal vulnerability in Systematic Iris Webforms 5.4
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal.
network
low complexity
systematic CWE-22
5.3