Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-10-25 CVE-2022-39345 Path Traversal vulnerability in Gin-Vue-Admin Project Gin-Vue-Admin
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack.
network
low complexity
gin-vue-admin-project CWE-22
7.5
2022-10-18 CVE-2022-42188 Path Traversal vulnerability in Lavalite 9.0.0
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
network
low complexity
lavalite CWE-22
7.5
2022-10-18 CVE-2022-39058 Path Traversal vulnerability in Changingtec Rava Certificate Validation System 3
RAVA certification validation system has a path traversal vulnerability.
network
low complexity
changingtec CWE-22
7.5
2022-10-17 CVE-2022-22128 Path Traversal vulnerability in Tableau Server
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release.
network
low complexity
tableau CWE-22
critical
9.8
2022-10-17 CVE-2022-23770 Path Traversal vulnerability in Wisa Smart Wing CMS 1905
This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors.
network
low complexity
wisa CWE-22
critical
9.8
2022-10-17 CVE-2022-3060 Path Traversal vulnerability in Gitlab
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests
network
low complexity
gitlab CWE-22
7.3
2022-10-14 CVE-2021-22685 Path Traversal vulnerability in Cassianetworks Access Controller
An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.
network
low complexity
cassianetworks CWE-22
7.5
2022-10-13 CVE-2021-20030 Path Traversal vulnerability in Sonicwall Global Management System
SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files.
network
low complexity
sonicwall CWE-22
7.5
2022-10-12 CVE-2022-33937 Path Traversal vulnerability in Dell Geodrive
Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function.
local
low complexity
dell CWE-22
7.1
2022-10-11 CVE-2022-34426 Path Traversal vulnerability in Dell Container Storage Modules 1.3.0
Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection.
network
low complexity
dell CWE-22
8.8