Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-08-09 CVE-2023-31450 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the SQL v2 sensors into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2023-08-08 CVE-2023-36534 Path Traversal vulnerability in Zoom
Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.
network
low complexity
zoom CWE-22
critical
9.8
2023-08-08 CVE-2023-37646 Path Traversal vulnerability in Bitberry File Opener 23.0
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
local
low complexity
bitberry CWE-22
7.8
2023-08-08 CVE-2023-24698 Path Traversal vulnerability in Foswiki
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request.
network
low complexity
foswiki CWE-22
7.5
2023-08-08 CVE-2023-33756 Path Traversal vulnerability in Foswiki
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
network
low complexity
foswiki CWE-22
7.5
2023-08-07 CVE-2023-36220 Path Traversal vulnerability in Textpattern 4.8.8
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.
network
low complexity
textpattern CWE-22
7.2
2023-08-05 CVE-2023-4172 Path Traversal vulnerability in Cdwanjiang Flash Flood Disaster Monitoring and Warning System 2.0
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0.
network
low complexity
cdwanjiang CWE-22
7.5
2023-08-04 CVE-2020-26065 Path Traversal vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests.
network
low complexity
cisco CWE-22
6.5
2023-08-04 CVE-2023-39143 Path Traversal vulnerability in Papercut MF
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.
network
low complexity
papercut CWE-22
critical
9.8
2023-08-04 CVE-2023-38708 Path Traversal vulnerability in Pimcore
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce.
network
low complexity
pimcore CWE-22
8.8