Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-07-10 CVE-2023-1183 Path Traversal vulnerability in multiple products
A flaw was found in the Libreoffice package.
local
low complexity
libreoffice fedoraproject redhat CWE-22
5.5
2023-07-10 CVE-2023-37288 Path Traversal vulnerability in Smartsoft Smartbpm.Net 6.70
SmartBPM.NET component has a vulnerability of path traversal within its file download function.
network
low complexity
smartsoft CWE-22
7.5
2023-07-06 CVE-2023-36460 Path Traversal vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub.
network
low complexity
joinmastodon CWE-22
critical
9.9
2023-07-06 CVE-2023-23547 Path Traversal vulnerability in Milesight Ur32L Firmware 32.3.0.5
A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5.
network
low complexity
milesight CWE-22
6.5
2023-07-06 CVE-2023-23907 Path Traversal vulnerability in Milesight Milesightvpn 2.0.2
A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2.
network
low complexity
milesight CWE-22
7.5
2023-07-06 CVE-2020-21862 Path Traversal vulnerability in Duxcms Project Duxcms 2.1
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
network
low complexity
duxcms-project CWE-22
8.1
2023-07-06 CVE-2023-30678 Path Traversal vulnerability in Samsung Calendar
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
local
low complexity
samsung CWE-22
5.5
2023-07-06 CVE-2023-24256 Path Traversal vulnerability in NIO Aspen 3.2.5
An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.
local
low complexity
nio CWE-22
7.8
2023-07-05 CVE-2023-36822 Path Traversal vulnerability in Uptime-Kuma Project Uptime-Kuma
Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1.
network
low complexity
uptime-kuma-project CWE-22
8.1
2023-07-05 CVE-2023-36827 Path Traversal vulnerability in Ethyca Fides
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code.
network
low complexity
ethyca CWE-22
7.5