Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2025-01-08 CVE-2023-52953 Path Traversal vulnerability in Huawei Emui and Harmonyos
Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
network
low complexity
huawei CWE-22
critical
9.1
2025-01-07 CVE-2024-12152 The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.5 via the 'mipl_wc_sync_download_log' action.
network
low complexity
CWE-22
7.5
2025-01-07 CVE-2024-12849 The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action.
network
low complexity
CWE-22
7.5
2025-01-04 CVE-2024-41765 IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system.
network
low complexity
CWE-22
6.5
2024-12-31 CVE-2024-12105 Path Traversal vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
network
low complexity
progress CWE-22
6.5
2024-12-24 CVE-2024-12850 The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function.
network
low complexity
CWE-22
4.9
2024-12-23 CVE-2024-53961 ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read.
network
high complexity
CWE-22
7.4
2024-12-20 CVE-2024-12830 Path Traversal vulnerability in Arista NG Firewall 17.1.1
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability.
network
low complexity
arista CWE-22
7.3
2024-12-19 CVE-2024-12793 Path Traversal vulnerability in Pbootcms
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3.
network
low complexity
pbootcms CWE-22
4.3
2024-12-19 CVE-2021-26102 Path Traversal vulnerability in Fortinet Fortiwan
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request.
network
low complexity
fortinet CWE-22
critical
9.1