Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-22
Total 5025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8009 1 Motu 21 112d, 1248, 16a and 18 more 2020-02-06 5.0 MEDIUM 7.5 HIGH
AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
CVE-2019-4674 1 Ibm 1 Security Identity Manager 2020-02-06 4.0 MEDIUM 4.9 MEDIUM
IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.
CVE-2020-8545 1 Circl 1 Ail Framework 2020-02-06 5.0 MEDIUM 7.5 HIGH
Global.py in AIL framework 2.8 allows path traversal.
CVE-2014-8799 1 Dukapress 1 Dukapress 2020-02-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.
CVE-2018-16836 1 Rubedo Project 1 Rubedo 2020-02-05 7.5 HIGH 9.8 CRITICAL
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.
CVE-2018-12476 1 Suse 3 Obs-service-tar Scm, Opensuse Factory, Suse Linux Enterprise Server 2020-02-05 6.4 MEDIUM 7.5 HIGH
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74:. openSUSE Factory obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74.
CVE-2013-6785 1 Supermicro 1 Intelligent Platform Management Interface 2020-02-04 4.0 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
CVE-2012-6609 1 Polycom 3 Hdx 8000, Hdx Video End Points, Uc Apl 2020-02-04 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
CVE-2013-4861 1 Micasaverde 2 Veralite, Veralite Firmware 2020-02-04 4.0 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.
CVE-2020-3717 1 Magento 1 Magento 2020-01-30 5.0 MEDIUM 5.3 MEDIUM
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2014-1923 1 Koha 1 Koha 2020-01-30 5.0 MEDIUM 7.5 HIGH
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via unspecified vectors.
CVE-2014-1922 1 Koha 1 Koha 2020-01-30 5.0 MEDIUM 7.5 HIGH
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2020-5221 1 Troglobit 1 Uftpd 2020-01-30 6.4 MEDIUM 7.2 HIGH
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has been fixed in version 2.11
CVE-2019-19893 1 Ixpdata 1 Easyinstall 2020-01-29 7.8 HIGH 7.5 HIGH
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
CVE-2013-2474 1 Aws-dms 1 Aws Xms 2020-01-29 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.
CVE-2014-8741 1 Lexmark 1 Markvision Enterprise 2020-01-29 10.0 HIGH 9.8 CRITICAL
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
CVE-2014-8742 1 Lexmark 1 Markvision Enterprise 2020-01-29 7.8 HIGH 7.5 HIGH
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2013-6056 1 Alienvault 1 Open Source Security Information Management 2020-01-29 7.8 HIGH 7.5 HIGH
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
CVE-2014-5007 1 Zohocorp 2 Manageengine Desktop Central, Manageengine Desktop Central Managed Service Providers 2020-01-29 10.0 HIGH 9.8 CRITICAL
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.
CVE-2019-14767 1 Dimo-crm 1 Yellowbox Crm 2020-01-28 5.0 MEDIUM 7.5 HIGH
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.