CWE:
 

Tytuł
Data
Autor
Med.
Barco Control Room Management Suite Directory Traversal
04.04.2022
Murat Aydemir
Med.
IdeaRE RefTree Path Traversal
31.03.2022
Savino Sisco
Med.
Joomla! 4.1.0 Zip Slip File Overwrite / Path Traversal
30.03.2022
EgiX
Med.
Xerte 3.10.3 Directory Traversal
02.03.2022
Rik Lutz
Med.
Kyocera Command Center RX ECOSYS M2035dn Directory Traversal File Disclosure (Unauthenticated)
14.02.2022
Luis Martinez
Med.
Kyocera Command Center RX ECOSYS M2035dn Directory Traversal
12.02.2022
Luis Martinez
Med.
Ethercreative Logs 3.0.3 Path Traversal
26.01.2022
Steffen Rogge
Med.
CoreFTP Server Build 725 Directory Traversal
10.01.2022
LiamInfosec
Med.
Grafana 8.3.0 Directory Traversal / Arbitrary File Read
09.12.2021
s1gh
High
Aviatrix Controller 6.x Path Traversal / Code Execution
11.10.2021
0xJoyGhosh
Med.
Apache HTTP Server 2.4.49 Path Traversal
06.10.2021
Lucas Souza
Med.
ECOA Building Automation System Directory Traversal
13.09.2021
Neurogenesia
Med.
Umbraco CMS 8.9.1 Path traversal and Arbitrary File Write (Authenticated)
13.09.2021
BitTheByte
Med.
Artica Proxy VMWare Appliance 4.30.000000 SP273 Path Traversal
06.09.2021
Heiko Feldhusen
Med.
OpenSIS 8.0 modname Directory/Path Traversal
05.09.2021
Eric Salario
Med.
OpenSIS 8.0 Directory Traversal
04.09.2021
Eric Salario
High
KevinLAB BEMS 1.0 Authenticated File Path Traversal / Information Disclosure
21.07.2021
LiquidWorm
Med.
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 Directory Traversal
07.07.2021
TheSmuggler
Med.
Pallets Werkzeug 0.15.4 Path Traversal
07.07.2021
faisalfs10x
Med.
OpenEMR 5.0.1.7 fileName Path Traversal (Authenticated)
29.06.2021
Ron Jost
Med.
Trixbox 2.8.0.4 Path Traversal
30.05.2021
Ron Jost
High
Schlix CMS 2.2.6-6 Shell Upload / Directory Traversal
25.05.2021
Emir Polat
Med.
Mini Mouse 9.2.0 Path Traversal
05.04.2021
gosh
Med.
WordPress Delightful Downloads Jquery File Tree 1.6.6 Path Traversal
22.03.2021
Nicholas Ferreira
Med.
Fluig 1.7.0 Path Traversal
05.03.2021
Lucas Souza
Med.
Yeastar TG400 GSM Gateway 91.3.0.3 Path Traversal
27.02.2021
SQSamir
Med.
orart Remote File Inculsion Vulnerability [ RFI ]
22.02.2021
h4shur
Med.
SolarWinds Serv-U FTP Server 15.2.1 Path Traversal
13.02.2021
Jack Misiura
Med.
Home Assistant Community Store 1.10.0 Path Traversal
29.01.2021
Lyghtnox
High
Selea Targa IP OCR-ANPR Camera Directory Traversal
22.01.2021
LiquidWorm
Med.
Apache Flink 1.11.0 Arbitrary File Read / Directory Traversal
08.01.2021
SunCSR
Med.
Responsive FileManager 9.13.4 Path Traversal
05.01.2021
SunCSR
Med.
WordPress Duplicator 1.3.26 Directory Traversal / File Read
03.01.2021
Hoa Nguyen
Med.
Rocket.Chat Path Traversal
23.12.2020
Moe Szyslak
Med.
Cisco ASA 9.14.1.10 / FTD 6.6.0.1 Path Traversal
15.12.2020
Freakyclown
Low
Advanced Component System (ACS) 1.0 Path Traversal
13.12.2020
Francisco Javier Santi...
Low
Huawei HedEx Lite (DM) Path Traversal
04.12.2020
S.AbenMassaoud
High
Sony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File Inclusion
04.12.2020
LiquidWorm
High
TestBox CFML Test Framework 4.1.0 Directory Traversal
21.11.2020
Darren King
Med.
PMB 5.6 Local File Disclosure / Directory Traversal
16.11.2020
41-trk
Med.
SIGE (Joomla) 3.4.1 & 3.5.3 Pro - Multiple Vulnerabilities
13.11.2020
h4shur
Med.
ReQuest Serious Play Media Player 3.0 Directory Traversal File Disclosure
05.11.2020
LiquidWorm
High
HiSilicon Video Encoder 1.97 File Disclosure / Path Traversal
19.10.2020
Alexei Kojenov
Med.
ReQuest Serious Play Media Player 3.0 File Disclosure / Path Traversal
19.10.2020
LiquidWorm
Med.
Cisco ASA and FTD 9.6.4.42 Path Traversal
14.10.2020
3ndG4me
High
Garfield Petshop 2020-10-01 Cross Site Request Forgery
09.10.2020
Ramdan Yantu
Med.
Karel IP Phone IP1211 Web Management Panel Directory Traversal
07.10.2020
Berat Gokberk ISLER
Med.
Ruijie Networks Switch eWeb S29_RGOS 11.4 Directory Traversal
20.08.2020
Tuygun
Med.
October CMS <= Build 465 Multiple Vulnerabilities
03.08.2020
Sivanesh Ashok
Med.
Files 4 Client Pro - Easy File Transfer v1.2.2 - Path Traversal
30.07.2020
Vlad Vector
Med.
Bludit 3.9.2 Directory Traversal
30.07.2020
James Green
Med.
Zyxel Armor X1 WAP6806 Directory Traversal
15.07.2020
Rajivarnan R
High
ATutor 2.2.4 Directory Traversal / Remote Code Execution
01.07.2020
liquidsky
Med.
Zyxel Armor X1 Model:WAP6806 - Directory Traversal
30.06.2020
Rajivarnan R
Med.
Cisco AnyConnect Path Traversal / Privilege Escalation
25.06.2020
Yorick Koster
Med.
OpenCTI 3.3.1 Cross Site Scripting / Directory Traversal
18.06.2020
Raif Berkay Dincel
Med.
MJML 4.6.2 Path Traversal
17.06.2020
Julien Ahrens
Med.
Navigate CMS 2.8.7 Authenticated Directory Traversal
10.06.2020
Gus Ralph
Med.
photobucket Library Slideshow - Remote File Inclusion
24.05.2020
h4shur
High
ManageEngine DataSecurity Plus Path Traversal / Code Execution
12.05.2020
Sahil Dhar
Med.
Booked Scheduler 2.7.7 Directory Traversal
09.05.2020
Besim Altinok
High
SimplePHPGal 0.7 Remote File Inclusion
06.05.2020
h4shur
Med.
Zen Load Balancer 3.10.1 Directory Traversal (Metasploit)
02.05.2020
Dhiraj Mishra
High
Gigamon GigaVUE 5.5.01.11 Directory Traversal / File Upload
30.04.2020
Balazs Hambalko
Med.
Easy Transfer 1.7 Cross Site Scripting / Directory Traversal
28.04.2020
Benjamin Kunz Mejri
Med.
Sky File 2.1.0 Cross Site Scripting / Directory Traversal
21.04.2020
Benjamin Kunz Mejri
Low
QRadar Community Edition 7.3.1.6 Path Traversal
21.04.2020
Yorick Koster
Med.
Zen Load Balancer 3.10.1 Directory Traversal
11.04.2020
Basim Alabdullah
Med.
LimeSurvey 4.1.11 File Manager Path Traversal
06.04.2020
Matthew Aberegg, Micha...
Med.
Joomla Fabrik 3.9.11 Directory Traversal
30.03.2020
qw3rTyTy
Med.
Jinfornet Jreport 15.6 Directory Traversal
27.03.2020
hongphukt
Med.
FIBARO System Home Center 5.021 Remote File Inclusion / XSS
24.03.2020
LiquidWorm
Med.
VMware Fusion Local Privilege Escalation / Directory Traversal
21.03.2020
Grimm
Med.
PHPKB Multi-Language 9 Authenticated Directory Traversal
16.03.2020
Antonio Cannito
Med.
Creative Contact Form 4.6.2 Directory Traversal
09.03.2020
Wolfgang Hotwagner
High
Apache ActiveMQ 5.11.1 Directory Traversal / Shell Upload
08.03.2020
David Jorm
Med.
Pachev FTP Server 1.0 Path Traversal
23.01.2020
1F98D
Med.
Citrix ADC / Gateway Path Traversal
17.01.2020
Mishra Dhiraj
Med.
Huawei HG255 Directory Traversal
16.01.2020
Ismail Tasdelen
Med.
Citrix ADC (NetScaler) Directory Traversal / Remote Code Execution
15.01.2020
Ramella Sebastien
Med.
piSignage 2.6.4 Directory Traversal
08.01.2020
JunYeong Ko
Med.
Voyager 1.3.0 Directory Traversal
07.01.2020
NgoAnhDuc
Med.
IBM InfoPrint 4247-Z03 Impact Matrix Printer Directory Traversal
01.01.2020
Raif Berkay Dincel
Med.
Bullwark Momentum Series JAWS 1.0 Directory Traversal
13.12.2019
Numan Türle
High
Bludit Directory Traversal Image File Upload (Metasploit)
04.12.2019
Anonymous
Med.
SALTO ProAccess SPACE 5.5 Traversal / File Write / XSS / Bypass
03.12.2019
W. Schober
Med.
Crystal Live HTTP Server 6.01 Directory Traversal
19.11.2019
numan turle
Med.
Lexmark Services Monitor 2.27.4.0.39 Directory Traversal
19.11.2019
Kevin Randall
Med.
gSOAP 2.8 Directory Traversal
14.11.2019
numan turle
High
Bludit Directory Traversal Image File Upload
13.11.2019
sinn3r
Med.
Jira Service Desk Server / Data Center Path Traversal
10.11.2019
Atlassian
High
Nostromo Directory Traversal Remote Command Execution (Metasploit)
04.11.2019
Quentin Kaiser
High
Nostromo 1.9.6 Directory Traversal / Remote Command Execution
01.11.2019
Quentin Kaiser
Med.
WordPress Arforms 3.7.1 Directory Traversal
27.10.2019
Ahmad Almorabea
High
Generic Zip Slip Traversal
12.09.2019
sinn3r
Med.
Tibco JasperSoft Path Traversal
10.09.2019
Elar Lang
Med.
Totaljs CMS 12.0 Path Traversal
05.09.2019
Riccardo Krauter
Med.
Nimble Streamer 3.0.2-2 < 3.5.4-9 Directory Traversal
23.08.2019
MAYASEVEN
High
Cisco Adaptive Security Appliance Path Traversal (Metasploit)
13.08.2019
Anonymous
High
Veritas Resiliency Platform (VRP) Traversal / Command Execution
01.08.2019
David Dillard


Common Weakness Enumeration (CWE)

CVE
Szczegóły
Opis
2022-05-16
Waiting for details
CVE-2022-1560

Updating...
 

 
The Amministrazione Aperta WordPress plugin through 3.7.3 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenticated users can exploit this, however the affected file generates a fatal error when accessed directly and the affected code is not reached. The issue can be exploited via the dashboard when logged in as an admin, or by making a logged in admin open a malicious link

 
2022-05-13
Waiting for details
CVE-2021-33005

Updating...
 

 
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.

 
2022-05-12
Medium
CVE-2022-29298

Updating...
 

 
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

 
2022-05-10
Medium
CVE-2022-1476

Vendor: Servmask
Software: All-in-one w...
 

 
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.

 
2022-05-09
Medium
CVE-2022-30333

Updating...
 

 
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

 
2022-05-05
Low
CVE-2021-45783

Updating...
 

 
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.

 
Medium
CVE-2021-42183

Vendor: Masacms
Software: Masacms
 

 
MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

 
Low
CVE-2022-29474

Vendor: F5
Software: Big-ip local...
 

 
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerability exists in iControl SOAP that allows an authenticated attacker with at least guest role privileges to read wsdl files in the BIG-IP file system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

 
Low
CVE-2022-26835

Vendor: F5
Software: Big-ip local...
 

 
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, directory traversal vulnerabilities exist in undisclosed iControl REST endpoints and TMOS Shell (tmsh) commands in F5 BIG-IP Guided Configuration, which may allow an authenticated attacker with at least resource administrator role privileges to read arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

 
Medium
CVE-2021-38693

Vendor: QNAP
Software: Qutscloud
 

 
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, QTS, QVR Pro Appliance: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1949 build 20220215 and later QuTS hero h4.5.4.1951 build 20220218 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later

 

 


Copyright 2022, cxsecurity.com

 

Back to Top