Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-03-20 CVE-2023-41877 Path Traversal vulnerability in Geoserver
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
network
low complexity
geoserver CWE-22
7.2
2024-03-08 CVE-2024-23216 Path Traversal vulnerability in Apple Macos
A path handling issue was addressed with improved validation.
local
low complexity
apple CWE-22
7.1
2024-03-04 CVE-2024-27199 Path Traversal vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
network
low complexity
jetbrains CWE-22
7.3
2024-02-21 CVE-2024-1704 Path Traversal vulnerability in Crmeb 5.2.2
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2.
low complexity
crmeb CWE-22
8.1
2024-02-21 CVE-2024-1703 Path Traversal vulnerability in Crmeb 5.2.2
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2.
network
low complexity
crmeb CWE-22
5.3
2024-02-21 CVE-2024-1708 Path Traversal vulnerability in Connectwise Screenconnect 22.7/23.8.4/23.8.5
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
network
low complexity
connectwise CWE-22
8.4
2024-02-21 CVE-2023-50955 Path Traversal vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system.
network
low complexity
ibm CWE-22
2.7
2024-02-20 CVE-2023-42791 Path Traversal vulnerability in Fortinet Fortimanager
A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
network
low complexity
fortinet CWE-22
8.8
2024-02-15 CVE-2024-23477 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-14 CVE-2023-35003 Path Traversal vulnerability in Intel Virtual Raid on CPU 8.0.0.4035
Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-22
7.8