Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-16 | CVE-2021-42797 | Path Traversal vulnerability in Aveva Edge 2020/8.1 Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources. | 7.5 |
2023-12-15 | CVE-2023-6831 | Path Traversal vulnerability in Lfprojects Mlflow Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2. | 8.1 |
2023-12-14 | CVE-2023-44278 | Path Traversal vulnerability in Dell products Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. | 6.7 |
2023-12-14 | CVE-2023-48660 | Path Traversal vulnerability in Dell products Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. | 7.5 |
2023-12-13 | CVE-2023-43586 | Path Traversal vulnerability in Zoom products Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access. | 8.8 |
2023-12-12 | CVE-2023-49089 | Path Traversal vulnerability in Umbraco CMS Umbraco is an ASP.NET content management system (CMS). | 6.5 |
2023-12-12 | CVE-2023-28465 | Path Traversal vulnerability in Hapifhir HL7 Fhir Core The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. | 7.5 |
2023-12-12 | CVE-2023-46455 | Path Traversal vulnerability in Gl-Inet Gl-Ar300M Firmware 4.3.7 In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality. | 7.5 |
2023-12-12 | CVE-2023-45316 | Path Traversal vulnerability in Mattermost Server Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack. | 8.8 |
2023-12-12 | CVE-2023-36654 | Path Traversal vulnerability in Prolion Cryptospike 3.0.15 Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters. | 6.5 |