Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-02-15 CVE-2024-25123 Path Traversal vulnerability in Open-Mss Mission Support System
MSS (Mission Support System) is an open source package designed for planning atmospheric research flights.
network
low complexity
open-mss CWE-22
7.5
2024-02-15 CVE-2024-23477 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-15 CVE-2024-25620 Path Traversal vulnerability in Helm
Helm is a tool for managing Charts.
network
low complexity
helm CWE-22
6.4
2024-02-14 CVE-2024-23607 Path Traversal vulnerability in F5 F5Os-A and F5Os-C
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
local
low complexity
f5 CWE-22
5.5
2024-02-14 CVE-2023-35003 Path Traversal vulnerability in Intel Virtual Raid on CPU 8.0.0.4035
Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-22
7.8
2024-02-14 CVE-2024-23787 Path Traversal vulnerability in Sharp Jh-Rv11 Firmware and Jh-Rvb1 Firmware
Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.
low complexity
sharp CWE-22
6.5
2024-02-14 CVE-2024-25125 Path Traversal vulnerability in Treasuredata Digdag
Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms.
network
low complexity
treasuredata CWE-22
5.3
2024-02-14 CVE-2024-1485 Path Traversal vulnerability in multiple products
A flaw was found in the decompression function of registry-support.
network
low complexity
redhat devfile CWE-22
critical
9.3
2024-02-13 CVE-2024-1082 Path Traversal vulnerability in Github Enterprise Server
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a specially crafted artifact tarball.
network
low complexity
github CWE-22
6.5
2024-02-13 CVE-2024-1163 Path Traversal vulnerability in Mapshaper
The attacker may exploit a path traversal vulnerability leading to information disclosure.
local
low complexity
mapshaper CWE-22
7.1