Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-12-16 CVE-2021-42797 Path Traversal vulnerability in Aveva Edge 2020/8.1
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
network
low complexity
aveva CWE-22
7.5
2023-12-15 CVE-2023-6831 Path Traversal vulnerability in Lfprojects Mlflow
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
network
low complexity
lfprojects CWE-22
8.1
2023-12-14 CVE-2023-44278 Path Traversal vulnerability in Dell products
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability.
local
low complexity
dell CWE-22
6.7
2023-12-14 CVE-2023-48660 Path Traversal vulnerability in Dell products
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability.
network
low complexity
dell CWE-22
7.5
2023-12-13 CVE-2023-43586 Path Traversal vulnerability in Zoom products
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
network
low complexity
zoom CWE-22
8.8
2023-12-12 CVE-2023-49089 Path Traversal vulnerability in Umbraco CMS
Umbraco is an ASP.NET content management system (CMS).
network
low complexity
umbraco CWE-22
6.5
2023-12-12 CVE-2023-28465 Path Traversal vulnerability in Hapifhir HL7 Fhir Core
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker.
network
low complexity
hapifhir CWE-22
7.5
2023-12-12 CVE-2023-46455 Path Traversal vulnerability in Gl-Inet Gl-Ar300M Firmware 4.3.7
In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.
network
low complexity
gl-inet CWE-22
7.5
2023-12-12 CVE-2023-45316 Path Traversal vulnerability in Mattermost Server
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.
network
low complexity
mattermost CWE-22
8.8
2023-12-12 CVE-2023-36654 Path Traversal vulnerability in Prolion Cryptospike 3.0.15
Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.
network
low complexity
prolion CWE-22
6.5