Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-04-20 CVE-2019-11378 Path Traversal vulnerability in Projectsend R1053
An issue was discovered in ProjectSend r1053.
network
low complexity
projectsend CWE-22
8.8
2019-04-18 CVE-2019-9005 Path Traversal vulnerability in Cprime Power Scripts
The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal.
network
low complexity
cprime CWE-22
6.5
2019-04-18 CVE-2019-3398 Path Traversal vulnerability in Atlassian Confluence
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
network
low complexity
atlassian CWE-22
8.8
2019-04-18 CVE-2019-1835 Path Traversal vulnerability in Cisco Aironet Access Point Firmware 8.8/8.9
A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP.
local
low complexity
cisco CWE-22
4.4
2019-04-15 CVE-2019-4178 Path Traversal vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
critical
9.1
2019-04-10 CVE-2019-3943 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces.
network
low complexity
mikrotik CWE-22
8.1
2019-04-10 CVE-2019-10945 Path Traversal vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.5.
network
low complexity
joomla CWE-22
critical
9.8
2019-04-09 CVE-2018-19586 Path Traversal vulnerability in Silverpeas
Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call.
network
low complexity
silverpeas CWE-22
critical
9.9
2019-04-09 CVE-2019-3880 Path Traversal vulnerability in multiple products
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API.
network
low complexity
samba debian redhat fedoraproject opensuse CWE-22
5.4
2019-04-09 CVE-2019-10242 Path Traversal vulnerability in Eclipse Kura
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
network
low complexity
eclipse CWE-22
5.3