Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-05-26 CVE-2023-32676 Path Traversal vulnerability in Autolabproject Autolab
Autolab is a course management service that enables auto-graded programming assignments.
network
low complexity
autolabproject CWE-22
7.2
2023-05-26 CVE-2023-27311 Path Traversal vulnerability in Netapp Blue XP Connector
NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing.
network
low complexity
netapp CWE-22
5.3
2023-05-26 CVE-2023-2825 Path Traversal vulnerability in Gitlab 16.0.0
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.
network
low complexity
gitlab CWE-22
7.5
2023-05-26 CVE-2022-46945 Path Traversal vulnerability in Nagvis
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
network
low complexity
nagvis CWE-22
6.5
2023-05-26 CVE-2023-28382 Path Traversal vulnerability in Et-X ESS REC
Directory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alter an arbitrary file on the server.
network
low complexity
et-x CWE-22
8.1
2023-05-25 CVE-2023-26215 Path Traversal vulnerability in Tibco EBX Add-Ons
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that are accessible to the web server.
network
low complexity
tibco CWE-22
6.5
2023-05-25 CVE-2023-26216 Path Traversal vulnerability in Tibco EBX Add-Ons
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server.
network
low complexity
tibco CWE-22
7.2
2023-05-25 CVE-2023-31861 Path Traversal vulnerability in Zlmediakit 4.0
ZLMediaKit 4.0 is vulnerable to Directory Traversal.
network
low complexity
zlmediakit CWE-22
7.5
2023-05-23 CVE-2023-27507 Path Traversal vulnerability in Microengine Mailform
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability.
network
low complexity
microengine CWE-22
critical
9.8
2023-05-23 CVE-2023-28408 Path Traversal vulnerability in MW WP Form Project MW WP Form 4.4.2
Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.
network
low complexity
mw-wp-form-project CWE-22
critical
9.8