Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-04-24 CVE-2019-7213 Path Traversal vulnerability in Smartertools Smartermail
SmarterTools SmarterMail 16.x before build 6985 allows directory traversal.
network
low complexity
smartertools CWE-22
6.5
2019-04-20 CVE-2019-11378 Path Traversal vulnerability in Projectsend R1053
An issue was discovered in ProjectSend r1053.
network
low complexity
projectsend CWE-22
8.8
2019-04-18 CVE-2019-9005 Path Traversal vulnerability in Cprime Power Scripts
The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal.
network
low complexity
cprime CWE-22
6.5
2019-04-18 CVE-2019-3398 Path Traversal vulnerability in Atlassian Confluence Server
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource.
network
low complexity
atlassian CWE-22
8.8
2019-04-18 CVE-2019-1835 Path Traversal vulnerability in Cisco Aironet Access Point Firmware 8.8/8.9
A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP.
local
low complexity
cisco CWE-22
4.4
2019-04-15 CVE-2019-4178 Path Traversal vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
critical
9.1
2019-04-10 CVE-2019-3943 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces.
network
low complexity
mikrotik CWE-22
8.1
2019-04-10 CVE-2019-10945 Path Traversal vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.5.
network
low complexity
joomla CWE-22
critical
9.8
2019-04-09 CVE-2018-19586 Path Traversal vulnerability in Silverpeas
Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call.
network
low complexity
silverpeas CWE-22
critical
9.9
2019-04-09 CVE-2019-3880 Path Traversal vulnerability in multiple products
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API.
network
low complexity
samba debian redhat fedoraproject opensuse CWE-22
5.4