Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-01-30 CVE-2024-22523 Path Traversal vulnerability in Fuwushe Ifair 23.8Ad0
Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.
network
low complexity
fuwushe CWE-22
7.5
2024-01-29 CVE-2023-30970 Path Traversal vulnerability in Palantir products
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
network
low complexity
palantir CWE-22
6.5
2024-01-29 CVE-2024-23827 Path Traversal vulnerability in Nginxui Nginx UI
Nginx-UI is a web interface to manage Nginx configurations.
network
low complexity
nginxui CWE-22
critical
9.8
2024-01-29 CVE-2024-0989 Path Traversal vulnerability in Kuerp Project Kuerp 1.0.4
A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4.
network
low complexity
kuerp-project CWE-22
critical
9.8
2024-01-27 CVE-2024-0697 Path Traversal vulnerability in Softaculous Backuply
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function.
network
low complexity
softaculous CWE-22
4.9
2024-01-26 CVE-2024-0402 Path Traversal vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.
network
low complexity
gitlab CWE-22
critical
9.9
2024-01-25 CVE-2023-41474 Path Traversal vulnerability in Ivanti Avalanche 6.3.4.153
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
network
low complexity
ivanti CWE-22
6.5
2024-01-25 CVE-2024-0882 Path Traversal vulnerability in Linkwechat 5.1.0
A vulnerability was found in qwdigital LinkWechat 5.1.0.
network
low complexity
linkwechat CWE-22
7.5
2024-01-25 CVE-2023-52076 Path Traversal vulnerability in Mate-Desktop Atril
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux.
local
low complexity
mate-desktop CWE-22
7.8
2024-01-25 CVE-2023-50785 Path Traversal vulnerability in Zohocorp Manageengine Adaudit Plus 7.2
Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
network
low complexity
zohocorp CWE-22
2.7