Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-08-30 CVE-2023-41040 Path Traversal vulnerability in Gitpython Project Gitpython
GitPython is a python library used to interact with Git repositories.
network
low complexity
gitpython-project CWE-22
6.5
2023-08-30 CVE-2023-40597 Path Traversal vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
local
low complexity
splunk CWE-22
8.8
2023-08-29 CVE-2023-39559 Path Traversal vulnerability in Web-Audimex Audimexee 15.0
AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.
network
low complexity
web-audimex CWE-22
5.3
2023-08-29 CVE-2023-20890 Path Traversal vulnerability in VMWare Aria Operations for Networks
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.
network
low complexity
vmware CWE-22
7.2
2023-08-28 CVE-2023-40826 Path Traversal vulnerability in Pf4J Project Pf4J
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.
network
low complexity
pf4j-project CWE-22
7.5
2023-08-28 CVE-2023-40827 Path Traversal vulnerability in Pf4J Project Pf4J
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter.
network
low complexity
pf4j-project CWE-22
7.5
2023-08-28 CVE-2023-40828 Path Traversal vulnerability in Pf4J Project Pf4J
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip method in the extract function.
network
low complexity
pf4j-project CWE-22
7.5
2023-08-28 CVE-2023-39810 Path Traversal vulnerability in Busybox 1.30.1/1.33.2
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
local
low complexity
busybox CWE-22
7.8
2023-08-25 CVE-2023-40587 Path Traversal vulnerability in multiple products
Pyramid is an open source Python web framework.
network
low complexity
agendaless fedoraproject CWE-22
5.3
2023-08-25 CVE-2023-3406 Path Traversal vulnerability in M-Files Classic web 23.2
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
network
low complexity
m-files CWE-22
6.5