Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-03-29 CVE-2024-25944 Path Traversal vulnerability in Dell Openmanage Enterprise
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability.
network
low complexity
dell CWE-22
7.5
2024-03-27 CVE-2023-0582 Path Traversal vulnerability in Forgerock Access Management 7.2.0
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
network
low complexity
forgerock CWE-22
critical
9.8
2024-03-26 CVE-2024-29196 Path Traversal vulnerability in PHPmyfaq 3.2.5
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases.
network
low complexity
phpmyfaq CWE-22
2.7
2024-03-21 CVE-2024-27921 Path Traversal vulnerability in Getgrav Grav
Grav is an open-source, flat-file content management system.
network
low complexity
getgrav CWE-22
8.8
2024-03-20 CVE-2023-41877 Path Traversal vulnerability in Geoserver
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
network
low complexity
geoserver CWE-22
7.2
2024-03-19 CVE-2024-21677 Path Traversal vulnerability in Atlassian Confluence Data Center and Confluence Server
This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center.
network
low complexity
atlassian CWE-22
8.8
2024-03-18 CVE-2024-27770 Path Traversal vulnerability in Unitronics Unilogic
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal
network
low complexity
unitronics CWE-22
8.8
2024-03-14 CVE-2024-25156 Path Traversal vulnerability in Fortra Goanywhere Managed File Transfer
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.
network
low complexity
fortra CWE-22
6.5
2024-03-13 CVE-2023-6825 Path Traversal vulnerability in Mndpsingh287 File Manager
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function.
network
low complexity
mndpsingh287 CWE-22
critical
9.9
2024-03-13 CVE-2024-1358 Path Traversal vulnerability in Webtechstreet Elementor Addon Elements
The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function.
network
low complexity
webtechstreet CWE-22
6.5