Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-11-21 CVE-2023-21418 Path Traversal vulnerability in Axis products
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion.
network
low complexity
axis CWE-22
7.1
2023-11-20 CVE-2023-38879 Path Traversal vulnerability in Os4Ed Opensis 9.0
The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.
network
low complexity
os4ed CWE-22
7.5
2023-11-17 CVE-2023-48185 Path Traversal vulnerability in Terra-Mater Terra-Master
Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET request.
network
low complexity
terra-mater CWE-22
7.5
2023-11-17 CVE-2023-42428 Path Traversal vulnerability in Cubecart
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.
network
low complexity
cubecart CWE-22
6.5
2023-11-17 CVE-2023-47283 Path Traversal vulnerability in Cubecart
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
network
low complexity
cubecart CWE-22
4.9
2023-11-17 CVE-2023-45382 Path Traversal vulnerability in Common-Services Sonice Retour 2.1.0
In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
network
low complexity
common-services CWE-22
7.5
2023-11-16 CVE-2023-6021 Path Traversal vulnerability in RAY Project RAY
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.
network
low complexity
ray-project CWE-22
7.5
2023-11-16 CVE-2023-6023 Path Traversal vulnerability in Vertaai Modeldb
An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.
network
low complexity
vertaai CWE-22
7.5
2023-11-15 CVE-2023-34062 Path Traversal vulnerability in Pivotal Reactor Netty
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.
network
low complexity
pivotal CWE-22
7.5
2023-11-14 CVE-2022-27229 Path Traversal vulnerability in Intel Hdmi Firmware
Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-22
7.8