Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2019-03-22 CVE-2019-9648 Path Traversal vulnerability in Coreftp Core FTP 2.0
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674.
network
low complexity
coreftp CWE-22
5.3
2019-03-21 CVE-2019-9889 Path Traversal vulnerability in Vanillaforums Vanilla
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class.
network
low complexity
vanillaforums CWE-22
2.7
2019-03-21 CVE-2019-6714 Path Traversal vulnerability in Blogengine Blogengine.Net 3.3/3.3.5.0/3.3.6.0
An issue was discovered in BlogEngine.NET through 3.3.6.0.
network
low complexity
blogengine CWE-22
critical
9.8
2019-03-21 CVE-2019-6274 Path Traversal vulnerability in Gl-Inet Gl-Ar300M-Lite Firmware 2.27
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.
network
low complexity
gl-inet CWE-22
8.8
2019-03-21 CVE-2019-6273 Path Traversal vulnerability in Gl-Inet Gl-Ar300M-Lite Firmware 2.27
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
network
low complexity
gl-inet CWE-22
6.5
2019-03-21 CVE-2019-5417 Path Traversal vulnerability in Zeit Serve
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.
network
low complexity
zeit CWE-22
7.5
2019-03-21 CVE-2019-5416 Path Traversal vulnerability in Localhost-Now Project Localhost-Now 1.0.2
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
network
low complexity
localhost-now-project CWE-22
7.5
2019-03-21 CVE-2019-0191 Path Traversal vulnerability in Apache Karaf
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file.
network
low complexity
apache CWE-22
6.5
2019-03-21 CVE-2018-20647 Path Traversal vulnerability in CAR Rental Script Project CAR Rental Script 2.0.8
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.
network
low complexity
car-rental-script-project CWE-22
6.5
2019-03-21 CVE-2018-20646 Path Traversal vulnerability in Basic B2B Script Project Basic B2B Script 2.0.9
PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory.
network
low complexity
basic-b2b-script-project CWE-22
6.5