Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-26 | CVE-2023-32522 | Path Traversal vulnerability in Trendmicro Mobile Security 9.8 A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | 8.1 |
2023-06-26 | CVE-2023-32557 | Path Traversal vulnerability in Trendmicro Apex ONE A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges. | 9.8 |
2023-06-26 | CVE-2023-25306 | Path Traversal vulnerability in Multimc 0.7.0 MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal. | 7.5 |
2023-06-26 | CVE-2023-25307 | Path Traversal vulnerability in Mrpack-Install Project Mrpack-Install nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal. | 7.8 |
2023-06-26 | CVE-2023-36301 | Path Traversal vulnerability in Talend Data Catalog 7.320210930 Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet. | 7.5 |
2023-06-25 | CVE-2023-36612 | Path Traversal vulnerability in Basecamp 3.26.3/4.2.0 Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an attacker to write arbitrary files in the application's private directory. | 7.5 |
2023-06-23 | CVE-2023-35801 | Path Traversal vulnerability in Safe FME Server A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. | 8.1 |
2023-06-22 | CVE-2023-34939 | Path Traversal vulnerability in Onlyoffice Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx. | 9.8 |
2023-06-19 | CVE-2023-35843 | Path Traversal vulnerability in Nocodb 0.106.1 NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. | 7.5 |
2023-06-19 | CVE-2023-35852 | Path Traversal vulnerability in Oisf Suricata In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. | 7.5 |