Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-08-17 CVE-2023-26469 Path Traversal vulnerability in Jorani 1.0.0
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
network
low complexity
jorani CWE-22
critical
9.8
2023-08-17 CVE-2023-2915 Path Traversal vulnerability in Rockwellautomation Thinmanager Thinserver 13.1.0
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function.
network
low complexity
rockwellautomation CWE-22
critical
9.1
2023-08-17 CVE-2023-2917 Path Traversal vulnerability in Rockwellautomation Thinmanager Thinserver 13.1.0
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function.
network
low complexity
rockwellautomation CWE-22
critical
9.8
2023-08-17 CVE-2023-3697 Path Traversal vulnerability in Asustor Data Master
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files.
network
low complexity
asustor CWE-22
8.8
2023-08-17 CVE-2023-3698 Path Traversal vulnerability in Asustor Data Master
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files.
network
low complexity
asustor CWE-22
8.1
2023-08-17 CVE-2023-34216 Path Traversal vulnerability in Moxa Tn-4900 Firmware and Tn-5900 Firmware
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability.
network
low complexity
moxa CWE-22
8.1
2023-08-17 CVE-2023-34217 Path Traversal vulnerability in Moxa Tn-4900 Firmware and Tn-5900 Firmware
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability.
network
low complexity
moxa CWE-22
8.1
2023-08-16 CVE-2023-20229 Path Traversal vulnerability in Cisco DUO Device Health Application
A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system. This vulnerability is due to insufficient input validation.
local
low complexity
cisco CWE-22
7.1
2023-08-16 CVE-2020-26037 Path Traversal vulnerability in Evenbalance Punkbuster 1.902
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
network
low complexity
evenbalance CWE-22
critical
9.8
2023-08-15 CVE-2023-32003 Path Traversal vulnerability in multiple products
`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack.
network
low complexity
nodejs fedoraproject CWE-22
5.3