Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-08-07 CVE-2024-37403 Path Traversal vulnerability in Ivanti Docs@Work
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability.
local
low complexity
ivanti CWE-22
5.5
2024-08-06 CVE-2024-39226 Path Traversal vulnerability in Gl-Inet products
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to manipulate routers by passing malicious shell commands through the s2s API.
network
low complexity
gl-inet CWE-22
critical
9.8
2024-08-06 CVE-2024-7564 Path Traversal vulnerability in Logsign Unified Secops Platform 6.4.11
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability.
network
low complexity
logsign CWE-22
6.5
2024-08-06 CVE-2024-7551 Path Traversal vulnerability in Juzaweb CMS
A vulnerability was found in juzaweb CMS up to 3.4.2.
network
low complexity
juzaweb CWE-22
4.9
2024-08-06 CVE-2024-6781 Path Traversal vulnerability in Calibre-Ebook Calibre
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
network
low complexity
calibre-ebook CWE-22
7.5
2024-08-05 CVE-2024-23657 Path Traversal vulnerability in Nuxt
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js.
network
low complexity
nuxt CWE-22
8.8
2024-08-04 CVE-2024-7458 Path Traversal vulnerability in Eladmin 2.7
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical.
network
low complexity
eladmin CWE-22
critical
9.8
2024-08-02 CVE-2024-41310 Path Traversal vulnerability in Yanzhenjie Andserver
AndServer 2.1.12 is vulnerable to Directory Traversal.
network
low complexity
yanzhenjie CWE-22
7.5
2024-08-02 CVE-2024-38878 Path Traversal vulnerability in Siemens Omnivise T3000 Application Server R9.2
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions).
network
low complexity
siemens CWE-22
6.5
2024-08-02 CVE-2024-7323 Path Traversal vulnerability in Digiwin Easyflow .Net
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input.
network
low complexity
digiwin CWE-22
6.5