Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-06-05 CVE-2023-33524 Path Traversal vulnerability in Advent Tamale RMS
Advent/SSC Inc.
network
low complexity
advent CWE-22
5.3
2023-06-05 CVE-2023-33690 Path Traversal vulnerability in Sonicjs 0.5.4/0.6.0/0.7.0
SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a backup CMS.
network
low complexity
sonicjs CWE-22
6.5
2023-06-05 CVE-2023-3098 Path Traversal vulnerability in Ubuntukylin Youker-Assistant
A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS.
local
low complexity
ubuntukylin CWE-22
7.8
2023-06-05 CVE-2023-34407 Path Traversal vulnerability in Harbingergroup Office Player 4.0.6.0.2
OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.
network
low complexity
harbingergroup CWE-22
7.5
2023-06-02 CVE-2023-3031 Path Traversal vulnerability in Webbax King-Avis
Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15.
network
low complexity
webbax CWE-22
4.9
2023-06-01 CVE-2023-27639 Path Traversal vulnerability in Tshirtecommerce Custom Product Designer
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop.
network
low complexity
tshirtecommerce CWE-22
7.5
2023-06-01 CVE-2023-27640 Path Traversal vulnerability in Tshirtecommerce Custom Product Designer
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop.
network
low complexity
tshirtecommerce CWE-22
7.5
2023-06-01 CVE-2023-29736 Path Traversal vulnerability in Timmystudios Keyboard Themes 1.275.1.164
Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.
network
low complexity
timmystudios CWE-22
critical
9.8
2023-06-01 CVE-2023-32714 Path Traversal vulnerability in Splunk and Splunk APP for Lookup File Editing
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.
network
low complexity
splunk CWE-22
8.1
2023-06-01 CVE-2023-33544 Path Traversal vulnerability in Hawt Hawtio 2.17.2
hawtio 2.17.2 is vulnerable to Path Traversal.
local
low complexity
hawt CWE-22
5.5