Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-48660 Path Traversal vulnerability in Dell products
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability.
network
low complexity
dell CWE-22
7.5
2023-12-14 CVE-2023-6407 Path Traversal vulnerability in Schneider-Electric Easy UPS Online Monitoring Software 2.5Gs/2.5Gs0122320
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
local
low complexity
schneider-electric CWE-22
7.1
2023-12-13 CVE-2023-43586 Path Traversal vulnerability in Zoom products
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
network
low complexity
zoom CWE-22
8.8
2023-12-13 CVE-2023-47624 Path Traversal vulnerability in Audiobookshelf
Audiobookshelf is a self-hosted audiobook and podcast server.
network
low complexity
audiobookshelf CWE-22
6.5
2023-12-13 CVE-2023-44251 Path Traversal vulnerability in Fortinet Fortiwan
** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1.
network
low complexity
fortinet CWE-22
8.8
2023-12-13 CVE-2023-6753 Path Traversal vulnerability in Lfprojects Mlflow
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.
network
low complexity
lfprojects CWE-22
8.8
2023-12-12 CVE-2023-49089 Path Traversal vulnerability in Umbraco CMS
Umbraco is an ASP.NET content management system (CMS).
network
low complexity
umbraco CWE-22
6.5
2023-12-12 CVE-2023-28465 Path Traversal vulnerability in Hapifhir HL7 Fhir Core
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker.
network
low complexity
hapifhir CWE-22
7.5
2023-12-12 CVE-2023-46455 Path Traversal vulnerability in Gl-Inet Gl-Ar300M Firmware 4.3.7
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
network
low complexity
gl-inet CWE-22
7.5
2023-12-12 CVE-2023-45316 Path Traversal vulnerability in Mattermost Server
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.
network
low complexity
mattermost CWE-22
8.8