Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2018-05-08 CVE-2018-1000175 Path Traversal vulnerability in Jenkins Html Publisher
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.
network
low complexity
jenkins CWE-22
6.5
2018-05-04 CVE-2018-5448 Path Traversal vulnerability in Medtronic 2090 Carelink Programmer Firmware
All versions of the Medtronic 2090 Carelink Programmer are affected by a directory traversal vulnerability where the product's software deployment network could allow an attacker to read files on the system.
low complexity
medtronic CWE-22
5.7
2018-05-03 CVE-2018-8003 Path Traversal vulnerability in Apache Ambari
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that is accessible by the user the Ambari Server is running as.
network
low complexity
apache CWE-22
5.3
2018-04-30 CVE-2018-10553 Path Traversal vulnerability in Nagios XI 5.4.13
An issue was discovered in Nagios XI 5.4.13.
network
low complexity
nagios CWE-22
6.5
2018-04-28 CVE-2017-18263 Path Traversal vulnerability in Seagate Personal Cloud Firmware 4.3.16.0/4.3.18.0
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
network
low complexity
seagate CWE-22
7.5
2018-04-27 CVE-2018-7669 Path Traversal vulnerability in Sitecore Sitecore.Net
An issue was discovered in Sitecore Sitecore.NET 8.1 rev.
network
low complexity
sitecore CWE-22
7.5
2018-04-26 CVE-2017-1723 Path Traversal vulnerability in IBM Qradar Security Information and Event Manager
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system.
network
low complexity
ibm CWE-22
6.5
2018-04-23 CVE-2018-9921 Path Traversal vulnerability in Cmsmadesimple CMS Made Simple 2.2.7
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum.
network
low complexity
cmsmadesimple CWE-22
5.3
2018-04-20 CVE-2018-10176 Path Traversal vulnerability in Digitalguardian Management Console 7.1.2.0015
Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
network
low complexity
digitalguardian CWE-22
6.5
2018-04-20 CVE-2014-10073 Path Traversal vulnerability in multiple products
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.
network
low complexity
wpitchoune debian CWE-22
7.5