Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-12-27 CVE-2020-36566 Path Traversal vulnerability in Tar-Utils Project Tar-Utils
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
network
low complexity
tar-utils-project CWE-22
critical
9.1
2022-12-27 CVE-2019-25087 Path Traversal vulnerability in Httpserver Project Httpserver
A vulnerability was found in RamseyK httpserver.
network
low complexity
httpserver-project CWE-22
7.5
2022-12-27 CVE-2022-4748 Path Traversal vulnerability in Flatpress
A vulnerability was found in FlatPress.
network
low complexity
flatpress CWE-22
critical
9.8
2022-12-26 CVE-2021-39369 Path Traversal vulnerability in Philips products
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
network
low complexity
philips CWE-22
6.5
2022-12-25 CVE-2022-44016 Path Traversal vulnerability in Simmeth Lieferantenmanager
An issue was discovered in Simmeth Lieferantenmanager before 5.6.
network
low complexity
simmeth CWE-22
7.5
2022-12-25 CVE-2022-45894 Path Traversal vulnerability in Planetestream Planet Estream
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
network
low complexity
planetestream CWE-22
6.5
2022-12-23 CVE-2022-23854 Path Traversal vulnerability in Aveva Intouch Access Anywhere 2020
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
network
low complexity
aveva CWE-22
7.5
2022-12-23 CVE-2022-47945 Path Traversal vulnerability in Thinkphp
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true).
network
low complexity
thinkphp CWE-22
critical
9.8
2022-12-23 CVE-2022-46171 Path Traversal vulnerability in Tauri
Tauri is a framework for building binaries for all major desktop platforms.
network
low complexity
tauri CWE-22
7.7
2022-12-23 CVE-2022-46492 Path Traversal vulnerability in Nbnbk Project Nbnbk
nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary.
network
low complexity
nbnbk-project CWE-22
6.5