Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-12-13 CVE-2022-20449 Path Traversal vulnerability in Google Android
In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error.
local
low complexity
google CWE-22
4.4
2022-12-13 CVE-2022-29580 Path Traversal vulnerability in Google Search
There exists a path traversal vulnerability in the Android Google Search app.
local
low complexity
google CWE-22
7.8
2022-12-12 CVE-2022-45269 Path Traversal vulnerability in Gmaolinx Linx Sphere 7.35.St15
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.
network
low complexity
gmaolinx CWE-22
7.5
2022-12-12 CVE-2022-37906 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated path traversal vulnerability exists in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-22
8.1
2022-12-12 CVE-2022-43518 Path Traversal vulnerability in Arubanetworks Edgeconnect Enterprise
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface.
network
low complexity
arubanetworks CWE-22
6.5
2022-12-12 CVE-2022-44532 Path Traversal vulnerability in Arubanetworks Edgeconnect Enterprise
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface.
network
low complexity
arubanetworks CWE-22
6.5
2022-12-12 CVE-2022-44653 Path Traversal vulnerability in Trendmicro Apex ONE 14.0.10349/2019
A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
local
low complexity
trendmicro CWE-22
7.8
2022-12-11 CVE-2022-4402 Path Traversal vulnerability in Docsys Project Docsys
A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37.
network
low complexity
docsys-project CWE-22
7.2
2022-12-09 CVE-2022-45290 Path Traversal vulnerability in Kbase DOC Project Kbase DOC 1.0
Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.
network
low complexity
kbase-doc-project CWE-22
critical
9.1
2022-12-08 CVE-2022-46826 Path Traversal vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
local
low complexity
jetbrains CWE-22
5.5