Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2020-27514 Path Traversal vulnerability in Zrlog 2.1.5
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).
network
low complexity
zrlog CWE-22
critical
9.1
2023-08-11 CVE-2021-26504 Path Traversal vulnerability in Dgtl Huemagic 3.0.0
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
network
low complexity
dgtl CWE-22
7.5
2023-08-10 CVE-2023-32563 Path Traversal vulnerability in Ivanti Avalanche
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
network
low complexity
ivanti CWE-22
critical
9.8
2023-08-10 CVE-2023-39964 Path Traversal vulnerability in Fit2Cloud 1Panel 1.4.3
1Panel is an open source Linux server operation and maintenance management panel.
network
low complexity
fit2cloud CWE-22
7.5
2023-08-09 CVE-2023-38997 Path Traversal vulnerability in Opnsense
A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.
network
low complexity
opnsense CWE-22
7.2
2023-08-09 CVE-2023-31448 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the HL7 sensor into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2023-08-09 CVE-2023-31449 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the WMI Custom sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the WMI Custom sensor into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2023-08-09 CVE-2023-31450 Path Traversal vulnerability in Paessler Prtg Network Monitor
A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the SQL v2 sensors into behaving differently for existing files and non-existing files.
network
low complexity
paessler CWE-22
4.7
2023-08-08 CVE-2023-36534 Path Traversal vulnerability in Zoom
Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.
network
low complexity
zoom CWE-22
critical
9.8
2023-08-08 CVE-2023-37646 Path Traversal vulnerability in Bitberry File Opener 23.0
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
local
low complexity
bitberry CWE-22
7.8