Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-08-28 CVE-2024-6312 Path Traversal vulnerability in Funnelforms Free
The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function.
network
low complexity
funnelforms CWE-22
6.5
2024-08-27 CVE-2024-3980 Path Traversal vulnerability in Hitachienergy Microscada PRO Sys600 and Microscada X Sys600
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations.
network
low complexity
hitachienergy CWE-22
8.8
2024-08-27 CVE-2024-6789 Path Traversal vulnerability in M-Files Server
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
network
low complexity
m-files CWE-22
6.5
2024-08-26 CVE-2024-8165 Path Traversal vulnerability in Beikeshop
A vulnerability, which was classified as problematic, was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5.
network
low complexity
beikeshop CWE-22
6.5
2024-08-26 CVE-2024-8163 Path Traversal vulnerability in Beikeshop
A vulnerability classified as critical was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5.
network
low complexity
beikeshop CWE-22
8.1
2024-08-23 CVE-2024-45189 Path Traversal vulnerability in Mage Mage-Ai
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Git Content" request
network
low complexity
mage CWE-22
6.5
2024-08-22 CVE-2023-7260 Path Traversal vulnerability in Opentext Cx-E Voice
Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4.
network
low complexity
opentext CWE-22
7.5
2024-08-22 CVE-2024-7634 Path Traversal vulnerability in F5 Nginx Agent and Nginx Instance Manager
NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
network
low complexity
f5 CWE-22
4.9
2024-08-21 CVE-2024-6141 Path Traversal vulnerability in Windscribe 2.9.9
Windscribe Directory Traversal Local Privilege Escalation Vulnerability.
local
low complexity
windscribe CWE-22
7.8
2024-08-21 CVE-2024-7600 Path Traversal vulnerability in Logsign Unified Secops Platform 6.4.20
Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability.
network
low complexity
logsign CWE-22
8.1