Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-14 | CVE-2023-22629 | Path Traversal vulnerability in Southrivertech Titan FTP Server An issue was discovered in TitanFTP through 1.94.1205. | 8.8 |
2023-02-14 | CVE-2023-23946 | Path Traversal vulnerability in Git-Scm GIT Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. | 7.5 |
2023-02-13 | CVE-2023-24188 | Path Traversal vulnerability in Ureport Project Ureport 2.2.9 ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. | 9.1 |
2023-02-13 | CVE-2023-24804 | Path Traversal vulnerability in Owncloud The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. | 4.4 |
2023-02-13 | CVE-2022-25937 | Path Traversal vulnerability in Glance Project Glance Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. | 6.5 |
2023-02-13 | CVE-2022-48323 | Path Traversal vulnerability in Sunlogin Sunflower 1.0.1.43315 Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. | 9.8 |
2023-02-09 | CVE-2023-24689 | Path Traversal vulnerability in Mojoportal 2.7.0.0 An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx | 4.3 |
2023-02-09 | CVE-2023-21448 | Path Traversal vulnerability in Samsung Cloud 4.7.0.3/5.1.0.8/5.2.00.7 Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file. | 3.3 |
2023-02-09 | CVE-2023-0745 | Path Traversal vulnerability in Yugabyte Yugabytedb Managed The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0 | 9.8 |
2023-02-07 | CVE-2021-36471 | Path Traversal vulnerability in Adminlte.Io Adminlte 3.1.0 Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. | 9.8 |