Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-33878 Path Traversal vulnerability in Intel Audio Install Package
Path transversal in some Intel(R) NUC P14E Laptop Element Audio Install Package software before version 156 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-22
7.8
2023-11-14 CVE-2023-45880 Path Traversal vulnerability in Gibbonedu Gibbon
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder.
network
low complexity
gibbonedu CWE-22
7.2
2023-11-10 CVE-2023-47246 Path Traversal vulnerability in Sysaid
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
network
low complexity
sysaid CWE-22
critical
9.8
2023-11-09 CVE-2023-45283 Path Traversal vulnerability in Golang GO
The filepath package does not recognize paths with a \??\ prefix as special.
network
low complexity
golang CWE-22
7.5
2023-11-09 CVE-2023-40054 Path Traversal vulnerability in Solarwinds Network Configuration Manager
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability.
network
low complexity
solarwinds CWE-22
8.8
2023-11-09 CVE-2023-40055 Path Traversal vulnerability in Solarwinds Network Configuration Manager
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability.
network
low complexity
solarwinds CWE-22
8.8
2023-11-09 CVE-2023-47613 Path Traversal vulnerability in Telit products
A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.
local
low complexity
telit CWE-22
7.1
2023-11-08 CVE-2023-36667 Path Traversal vulnerability in Couchbase Server
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
network
low complexity
couchbase CWE-22
7.5
2023-11-07 CVE-2023-46253 Path Traversal vulnerability in Squidex.Io Squidex 7.8.2
Squidex is an open source headless CMS and content management hub.
network
low complexity
squidex-io CWE-22
7.2
2023-11-06 CVE-2023-5355 Path Traversal vulnerability in Getawesomesupport Awesome Support
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
network
low complexity
getawesomesupport CWE-22
8.1