Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-06-25 CVE-2023-36612 Path Traversal vulnerability in Basecamp 3.26.3/4.2.0
Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an attacker to write arbitrary files in the application's private directory.
network
low complexity
basecamp CWE-22
7.5
2023-06-23 CVE-2023-35169 Path Traversal vulnerability in Webklex PHP-Imap
PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled.
network
low complexity
webklex CWE-22
critical
9.8
2023-06-23 CVE-2023-35801 Path Traversal vulnerability in Safe FME Server
A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files.
network
low complexity
safe CWE-22
8.1
2023-06-22 CVE-2023-34939 Path Traversal vulnerability in Onlyoffice
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
network
low complexity
onlyoffice CWE-22
critical
9.8
2023-06-19 CVE-2023-35843 Path Traversal vulnerability in Nocodb 0.106.1
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route.
network
low complexity
nocodb CWE-22
7.5
2023-06-19 CVE-2023-35852 Path Traversal vulnerability in Oisf Suricata
In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem.
network
low complexity
oisf CWE-22
7.5
2023-06-19 CVE-2023-35844 Path Traversal vulnerability in Lightdash
packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow ..
network
low complexity
lightdash CWE-22
7.5
2023-06-19 CVE-2023-35840 Path Traversal vulnerability in Std42 Elfinder
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
network
low complexity
std42 CWE-22
6.5
2023-06-16 CVE-2023-25186 Path Traversal vulnerability in Nokia Asika Airscale Firmware
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B.
local
low complexity
nokia CWE-22
2.8
2023-06-15 CVE-2023-34880 Path Traversal vulnerability in Cmseasy 7.7.7.7
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php.
network
low complexity
cmseasy CWE-22
critical
9.8