Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-10-04 CVE-2018-16457 Path Traversal vulnerability in Open Source Real-Estate Script Project Open Source Real-Estate Script 3.6.2
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.
5.3
2018-10-02 CVE-2018-12473 Path Traversal vulnerability in Opensuse Open Build Service
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build.
network
low complexity
opensuse CWE-22
7.5
2018-10-01 CVE-2018-17838 Path Traversal vulnerability in Jtbc PHP 3.0.1.6
An issue was discovered in JTBC(PHP) 3.0.1.6.
network
low complexity
jtbc CWE-22
7.5
2018-10-01 CVE-2018-17837 Path Traversal vulnerability in Jtbc PHP 3.0.1.6
An issue was discovered in JTBC(PHP) 3.0.1.6.
network
low complexity
jtbc CWE-22
7.5
2018-10-01 CVE-2018-17836 Path Traversal vulnerability in Jtbc PHP 3.0.1.6
An issue was discovered in JTBC(PHP) 3.0.1.6.
network
low complexity
jtbc CWE-22
8.8
2018-10-01 CVE-2018-17828 Path Traversal vulnerability in Zziplib Project Zziplib 0.13.69
Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a ..
local
low complexity
zziplib-project CWE-22
5.5
2018-09-30 CVE-2018-17798 Path Traversal vulnerability in Zzcms 8.3
An issue was discovered in zzcms 8.3.
network
low complexity
zzcms CWE-22
6.5
2018-09-30 CVE-2018-17797 Path Traversal vulnerability in Zzcms 8.3
An issue was discovered in zzcms 8.3.
network
low complexity
zzcms CWE-22
6.5
2018-09-30 CVE-2018-17785 Path Traversal vulnerability in Blynk Blynk-Server
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
network
low complexity
blynk CWE-22
7.5
2018-09-28 CVE-2018-9074 Path Traversal vulnerability in Lenovo Lenovoemc Firmware 4.1.402.34662
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal.
network
low complexity
lenovo CWE-22
6.5