Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-04-03 CVE-2019-5423 Path Traversal vulnerability in Http-Live-Simulator Project Http-Live-Simulator 1.0.5
Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on the file system by a remote attacker.
network
low complexity
http-live-simulator-project CWE-22
7.5
2019-04-02 CVE-2018-1618 Path Traversal vulnerability in IBM Security Privileged Identity Manager 2.1.1
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
7.5
2019-04-01 CVE-2019-5889 Path Traversal vulnerability in Overit Geocall 6.3
An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
network
low complexity
overit CWE-22
7.5
2019-04-01 CVE-2018-13299 Path Traversal vulnerability in Synology Calendar
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
network
low complexity
synology CWE-22
6.5
2019-03-29 CVE-2019-9922 Path Traversal vulnerability in Harmistechnology JE Messenger 1.2.2
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!.
network
low complexity
harmistechnology CWE-22
7.5
2019-03-28 CVE-2019-0225 Path Traversal vulnerability in Apache Jspwiki
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
network
low complexity
apache CWE-22
7.5
2019-03-28 CVE-2018-20144 Path Traversal vulnerability in Gitlab
GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.
network
low complexity
gitlab CWE-22
7.5
2019-03-27 CVE-2019-1010257 Path Traversal vulnerability in Article2Pdf Project Article2Pdf
An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27.
network
low complexity
article2pdf-project CWE-22
critical
9.1
2019-03-27 CVE-2019-5927 Path Traversal vulnerability in Weban AN
Directory traversal vulnerability in 'an' App for iOS Version 3.2.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
weban CWE-22
7.5
2019-03-27 CVE-2019-3828 Path Traversal vulnerability in Redhat Ansible
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
local
low complexity
redhat CWE-22
4.2