Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-04-10 CVE-2019-3943 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces.
network
low complexity
mikrotik CWE-22
8.1
2019-04-10 CVE-2019-10945 Path Traversal vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.5.
network
low complexity
joomla CWE-22
critical
9.8
2019-04-09 CVE-2018-19586 Path Traversal vulnerability in Silverpeas
Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call.
network
low complexity
silverpeas CWE-22
critical
9.9
2019-04-09 CVE-2019-3880 Path Traversal vulnerability in multiple products
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API.
network
low complexity
samba debian redhat fedoraproject opensuse CWE-22
5.4
2019-04-09 CVE-2019-10242 Path Traversal vulnerability in Eclipse Kura
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
network
low complexity
eclipse CWE-22
5.3
2019-04-09 CVE-2019-10632 Path Traversal vulnerability in Zyxel Nas326 Firmware 5.21
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
network
low complexity
zyxel CWE-22
6.5
2019-04-08 CVE-2019-1785 Path Traversal vulnerability in Clamav 0.101.0/0.101.1
A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.
local
low complexity
clamav CWE-22
7.8
2019-04-08 CVE-2014-5436 Path Traversal vulnerability in Honeywell Experion Process Knowledge System R400/R410/R430
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure.
network
low complexity
honeywell CWE-22
7.5
2019-04-05 CVE-2019-9489 Path Traversal vulnerability in Trendmicro products
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
network
low complexity
trendmicro CWE-22
7.5
2019-04-04 CVE-2018-20229 Path Traversal vulnerability in Gitlab
GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory Traversal.
network
low complexity
gitlab CWE-22
7.5