Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-11-11 CVE-2022-36400 Path Traversal vulnerability in Intel NUC KIT Wireless Adapter Driver Installer
Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-22
7.8
2022-11-09 CVE-2022-29836 Path Traversal vulnerability in Westerndigital products
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system.
network
low complexity
westerndigital CWE-22
4.3
2022-11-08 CVE-2022-20453 Path Traversal vulnerability in Google Android
In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error.
local
low complexity
google CWE-22
5.5
2022-11-08 CVE-2022-34822 Path Traversal vulnerability in NEC products
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially execute arbitrary code.
network
low complexity
nec CWE-22
critical
9.8
2022-11-07 CVE-2022-37865 Path Traversal vulnerability in Apache IVY 2.4.0/2.5.0
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging.
network
low complexity
apache CWE-22
critical
9.1
2022-11-04 CVE-2022-20962 Path Traversal vulnerability in Cisco Identity Services Engine 3.1
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation.
network
low complexity
cisco CWE-22
8.8
2022-11-03 CVE-2022-43451 Path Traversal vulnerability in Openharmony 3.1/3.1.1/3.1.2
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services.
local
low complexity
openharmony CWE-22
6.5
2022-11-02 CVE-2021-45448 Path Traversal vulnerability in Hitachi Vantara Pentaho 8.3.0.0/8.3.0.25/8.3.0.9
Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user-supplied path to access resources that are out of bounds.  The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
network
low complexity
hitachi CWE-22
6.5
2022-10-31 CVE-2021-40661 Path Traversal vulnerability in MT Ind780 Firmware 7.2.10/8.0.07
A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing Terminals Build 8.0.07 March 19, 2018 (SS Label 'IND780_8.0.07'), Version 7.2.10 June 18, 2012 (SS Label 'IND780_7.2.10').
network
low complexity
mt CWE-22
7.5
2022-10-28 CVE-2022-39367 Path Traversal vulnerability in Qtiworks Project Qtiworks 1.0
QTIWorks is a software suite for standards-based assessment delivery.
network
low complexity
qtiworks-project CWE-22
6.5