Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2023-02-26 CVE-2023-1044 Path Traversal vulnerability in Muyucms 2.2
A vulnerability was found in MuYuCMS 2.2.
network
low complexity
muyucms CWE-22
8.8
2023-02-26 CVE-2023-1045 Path Traversal vulnerability in Muyucms 2.2
A vulnerability was found in MuYuCMS 2.2.
network
low complexity
muyucms CWE-22
8.1
2023-02-25 CVE-2022-48362 Path Traversal vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet.
network
low complexity
zohocorp CWE-22
8.8
2023-02-22 CVE-2023-0104 Path Traversal vulnerability in Weintek Easybuilder PRO
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.
local
low complexity
weintek CWE-22
7.8
2023-02-22 CVE-2023-22973 Path Traversal vulnerability in Open-Emr Openemr
A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via the formname parameter.
network
low complexity
open-emr CWE-22
8.8
2023-02-22 CVE-2023-25579 Path Traversal vulnerability in Nextcloud Server
Nextcloud server is a self hosted home cloud product.
network
low complexity
nextcloud CWE-22
7.5
2023-02-22 CVE-2022-41216 Path Traversal vulnerability in Hybridsoftware Cloudflow 2.0.0/2.3.1
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.
network
low complexity
hybridsoftware CWE-22
6.5
2023-02-22 CVE-2023-23063 Path Traversal vulnerability in Cellinx NVT web Server 1.0.6.002B
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
network
low complexity
cellinx CWE-22
7.5
2023-02-21 CVE-2023-26265 Path Traversal vulnerability in Borg Project Borg
The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL.
network
low complexity
borg-project CWE-22
5.3
2023-02-16 CVE-2022-44299 Path Traversal vulnerability in Sscms Siteserver CMS 7.1.3
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
network
low complexity
sscms CWE-22
4.9