Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2024-12-31 CVE-2024-12105 Path Traversal vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
network
low complexity
progress CWE-22
6.5
2024-12-24 CVE-2024-12850 The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function.
network
low complexity
CWE-22
4.9
2024-12-23 CVE-2024-53961 Path Traversal vulnerability in Adobe Coldfusion 2021/2023
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read.
network
low complexity
adobe CWE-22
critical
9.8
2024-12-21 CVE-2024-12875 Path Traversal vulnerability in Awesomemotive Easy Digital Downloads
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality.
network
low complexity
awesomemotive CWE-22
4.9
2024-12-20 CVE-2024-12830 Path Traversal vulnerability in Arista NG Firewall 17.1.1
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability.
network
low complexity
arista CWE-22
7.3
2024-12-19 CVE-2024-12793 Path Traversal vulnerability in Pbootcms
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3.
network
low complexity
pbootcms CWE-22
4.3
2024-12-19 CVE-2021-26102 Path Traversal vulnerability in Fortinet Fortiwan
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request.
network
low complexity
fortinet CWE-22
critical
9.1
2024-12-16 CVE-2024-54382 Path Traversal vulnerability in Bold-Themes Bold Page Builder
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldThemes Bold Page Builder allows Path Traversal.This issue affects Bold Page Builder: from n/a through 5.1.5.
network
low complexity
bold-themes CWE-22
4.9
2024-12-12 CVE-2024-12482 Path Traversal vulnerability in Cjbi Wetech-Cms 1.0/1.1/1.2
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2.
network
low complexity
cjbi CWE-22
4.3
2024-12-10 CVE-2024-55550 Path Traversal vulnerability in Mitel Micollab
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization.
network
low complexity
mitel CWE-22
2.7