Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-22
Total 5025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-8238 3 Adobe, Apple, Microsoft 4 Acrobat Dc, Acrobat Reader Dc, Mac Os X and 1 more 2019-10-28 5.0 MEDIUM 7.5 HIGH
Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and earlier version; 2017.011.30138 and earlier version; 2015.006.30495 and earlier versions; 2015.006.30493 and earlier versions have a Path Traversal vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
CVE-2019-4400 1 Ibm 1 Cloud Orchestrator 2019-10-28 4.0 MEDIUM 4.3 MEDIUM
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162261.
CVE-2019-17109 1 Koji Project 1 Koji 2019-10-25 4.0 MEDIUM 6.5 MEDIUM
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
CVE-2019-15266 1 Cisco 1 Wireless Lan Controller Software 2019-10-22 2.1 LOW 4.4 MEDIUM
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.
CVE-2019-16279 1 Nazgul 1 Nostromo Nhttpd 2019-10-21 5.0 MEDIUM 7.5 HIGH
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
CVE-2019-14657 1 Yeahlink 6 T49g, T49g Firmware, T58v and 3 more 2019-10-18 9.0 HIGH 8.8 HIGH
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password replacement and arbitrary code execution as root.
CVE-2018-1000850 1 Squareup 1 Retrofit 2019-10-17 6.4 MEDIUM 7.5 HIGH
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.
CVE-2010-5334 1 Icewarp 1 Webclient 2019-10-17 7.8 HIGH 7.5 HIGH
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.
CVE-2019-17537 1 Jnoj 1 Jiangnan Online Judge 2019-10-16 6.4 MEDIUM 7.5 HIGH
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
CVE-2019-17538 1 Jnoj 1 Jiangnan Online Judge 2019-10-16 5.0 MEDIUM 7.5 HIGH
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
CVE-2018-1002204 1 Adm-zip Project 1 Adm-zip 2019-10-16 4.3 MEDIUM 5.5 MEDIUM
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVE-2015-9470 1 Ionadas 1 History Collection 2019-10-16 5.0 MEDIUM 7.5 HIGH
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
CVE-2010-5335 1 Icewarp 1 Webclient 2019-10-16 7.8 HIGH 7.5 HIGH
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.
CVE-2015-9463 1 S3bubble 1 S3bubble-amazon-s3-audio-streaming 2019-10-15 5.0 MEDIUM 7.5 HIGH
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
CVE-2015-9464 1 S3bubble 1 S3bubble-amazon-s3-html-5-video-with-adverts 2019-10-15 5.0 MEDIUM 7.5 HIGH
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
CVE-2015-9473 1 Estrutura-basica Project 1 Estrutura-basica 2019-10-15 5.0 MEDIUM 7.5 HIGH
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
CVE-2018-16202 1 Ionicframework 1 Ionic Web View 2019-10-15 5.0 MEDIUM 8.6 HIGH
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.
CVE-2015-9480 1 Robot-cpa 1 Robotcpa 2019-10-15 5.0 MEDIUM 7.5 HIGH
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
CVE-2019-17187 1 Fiberhome 2 Hg2201t, Hg2201t Firmware 2019-10-11 5.0 MEDIUM 7.5 HIGH
/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
CVE-2019-17399 1 Joomlashack 1 Shack Forms Pro 2019-10-11 7.5 HIGH 9.8 CRITICAL
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.