Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-06-28 CVE-2023-3330 Path Traversal vulnerability in NEC products
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to obtain specific files in the product.
network
low complexity
nec CWE-22
4.3
2023-06-28 CVE-2023-3331 Path Traversal vulnerability in NEC products
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to delete specific files in the product.
network
low complexity
nec CWE-22
5.4
2023-06-27 CVE-2020-19902 Path Traversal vulnerability in Wcms 0.3.2
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
network
low complexity
wcms CWE-22
critical
9.8
2023-06-26 CVE-2023-30945 Path Traversal vulnerability in Palantir products
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames.
network
low complexity
palantir CWE-22
critical
9.8
2023-06-26 CVE-2023-32521 Path Traversal vulnerability in Trendmicro Mobile Security 9.8
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.
network
low complexity
trendmicro CWE-22
critical
9.1
2023-06-26 CVE-2023-32522 Path Traversal vulnerability in Trendmicro Mobile Security 9.8
A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
network
low complexity
trendmicro CWE-22
8.1
2023-06-26 CVE-2023-32557 Path Traversal vulnerability in Trendmicro Apex ONE
A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges.
network
low complexity
trendmicro CWE-22
critical
9.8
2023-06-26 CVE-2023-25306 Path Traversal vulnerability in Multimc 0.7.0
MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal.
network
low complexity
multimc CWE-22
7.5
2023-06-26 CVE-2023-25307 Path Traversal vulnerability in Mrpack-Install Project Mrpack-Install
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
local
low complexity
mrpack-install-project CWE-22
7.8
2023-06-26 CVE-2023-36301 Path Traversal vulnerability in Talend Data Catalog 7.320210930
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
network
low complexity
talend CWE-22
7.5