Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-01-09 CVE-2018-0705 Path Traversal vulnerability in Cybozu Dezie
Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.
network
low complexity
cybozu CWE-22
critical
9.1
2019-01-09 CVE-2018-0704 Path Traversal vulnerability in Cybozu Office
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen.
network
low complexity
cybozu CWE-22
7.5
2019-01-09 CVE-2018-0703 Path Traversal vulnerability in Cybozu Office
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.
network
low complexity
cybozu CWE-22
7.5
2019-01-09 CVE-2018-0702 Path Traversal vulnerability in Cybozu Mailwise
Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.
network
low complexity
cybozu CWE-22
7.5
2019-01-07 CVE-2015-9275 Path Traversal vulnerability in ARC Project ARC 5.21Q
ARC 5.21q allows directory traversal via a full pathname in an archive file.
network
low complexity
arc-project CWE-22
5.3
2019-01-03 CVE-2019-3580 Path Traversal vulnerability in Openrefine
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
network
low complexity
openrefine CWE-22
7.5
2019-01-02 CVE-2018-15490 Path Traversal vulnerability in Expressvpn
An issue was discovered in ExpressVPN on Windows.
local
low complexity
expressvpn CWE-22
7.1
2018-12-31 CVE-2018-18593 Path Traversal vulnerability in HP Ucmdb Configuration Manager
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11.
network
low complexity
hp CWE-22
7.5
2018-12-30 CVE-2018-20610 Path Traversal vulnerability in Txjia Imcat 4.4
imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.
network
low complexity
txjia CWE-22
4.9
2018-12-30 CVE-2018-20604 Path Traversal vulnerability in Lfdycms LEI Feng TV CMS 3.8.6
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin.php?s=/Template/edit/path/*web*..*..*..*..*1.txt.html URI to read the 1.txt file.
network
low complexity
lfdycms CWE-22
4.9