Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-44255 Path Traversal vulnerability in Apple products
A path handling issue was addressed with improved logic.
local
low complexity
apple CWE-22
7.8
2024-10-25 CVE-2024-48224 Path Traversal vulnerability in Funadmin 5.0.2
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
network
low complexity
funadmin CWE-22
4.9
2024-10-25 CVE-2024-37847 Path Traversal vulnerability in Radixiot Mango and Mangoapi
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
network
low complexity
radixiot CWE-22
8.8
2024-10-25 CVE-2024-49381 Path Traversal vulnerability in Plenti
Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2.
network
low complexity
plenti CWE-22
7.5
2024-10-25 CVE-2024-10379 Path Traversal vulnerability in Esafenet CDG 5
A vulnerability classified as problematic was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-22
7.5
2024-10-25 CVE-2024-10011 Path Traversal vulnerability in Buddypress
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter.
network
low complexity
buddypress CWE-22
8.1
2024-10-25 CVE-2024-45842 Path Traversal vulnerability in multiple products
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.
network
low complexity
toshibatec sharp CWE-22
5.3
2024-10-24 CVE-2024-49359 Path Traversal vulnerability in Zimaspace Zimaos
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI.
network
low complexity
zimaspace CWE-22
7.5
2024-10-24 CVE-2024-49760 Path Traversal vulnerability in Openrefine
OpenRefine is a free, open source tool for working with messy data.
network
low complexity
openrefine CWE-22
5.3
2024-10-24 CVE-2024-47883 Path Traversal vulnerability in Openrefine Butterfly
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework.
network
low complexity
openrefine CWE-22
critical
9.1