Total
5025 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-16123 | 1 Kartatopia | 1 Piluscart | 2019-09-09 | 5.0 MEDIUM | 7.5 HIGH |
| In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure. | |||||
| CVE-2011-1572 | 1 Gitolite | 1 Gitolite | 2019-09-09 | 6.8 MEDIUM | N/A |
| Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands. | |||||
| CVE-2012-4506 | 2 Gitolite, Sitaram Chamarty | 2 Gitolite, Gitolite | 2019-09-09 | 4.6 MEDIUM | N/A |
| Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name. | |||||
| CVE-2019-16105 | 1 Silver-peak | 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware | 2019-09-09 | 4.0 MEDIUM | 4.9 MEDIUM |
| Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI. | |||||
| CVE-2019-15952 | 1 Totaljs | 1 Total.js Cms | 2019-09-06 | 6.5 MEDIUM | 8.8 HIGH |
| An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension. | |||||
| CVE-2019-15630 | 1 Mulesoft | 2 Api Gateway, Mule Runtime | 2019-09-05 | 5.0 MEDIUM | 7.5 HIGH |
| Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process. | |||||
| CVE-2019-15714 | 1 Entropic Project | 1 Entropic | 2019-09-04 | 5.0 MEDIUM | 5.3 MEDIUM |
| cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations. | |||||
| CVE-2019-6113 | 1 Onkyo | 2 Tx-nr686, Tx-nr686 Firmware | 2019-09-04 | 5.0 MEDIUM | 7.5 HIGH |
| Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI. | |||||
| CVE-2019-15822 | 1 Wpserveur | 1 Wps Child Theme Generator | 2019-09-03 | 7.5 HIGH | 9.8 CRITICAL |
| The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. | |||||
| CVE-2019-15519 | 1 Power-response Project | 1 Power-response | 2019-08-30 | 10.0 HIGH | 9.8 CRITICAL |
| Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. | |||||
| CVE-2019-11029 | 1 Mirasys | 1 Mirasys Vms | 2019-08-30 | 5.0 MEDIUM | 7.5 HIGH |
| Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. This includes SAM-database backups, Web.config files, etc. and might cause a serious impact on confidentiality. | |||||
| CVE-2017-18586 | 1 Insert Pages Project | 1 Insert Pages | 2019-08-29 | 6.4 MEDIUM | 9.1 CRITICAL |
| The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. | |||||
| CVE-2014-10390 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2019-08-29 | 6.4 MEDIUM | 9.1 CRITICAL |
| The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | |||||
| CVE-2019-12791 | 1 Vestacp | 1 Control Panel | 2019-08-28 | 9.0 HIGH | 8.8 HIGH |
| A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form. | |||||
| CVE-2019-15516 | 1 Cuberite | 1 Cuberite | 2019-08-27 | 5.0 MEDIUM | 7.5 HIGH |
| Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring. | |||||
| CVE-2018-14672 | 1 Yandex | 1 Clickhouse | 2019-08-27 | 5.0 MEDIUM | 5.3 MEDIUM |
| In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. | |||||
| CVE-2019-15517 | 1 Jc21 | 1 Nginx Proxy Manager | 2019-08-27 | 4.9 MEDIUM | 5.5 MEDIUM |
| jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. | |||||
| CVE-2019-11013 | 1 Softvelum | 1 Nimble Streamer | 2019-08-27 | 4.0 MEDIUM | 6.5 MEDIUM |
| Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server. | |||||
| CVE-2014-8871 | 1 Sap | 1 Hybris | 2019-08-27 | 5.0 MEDIUM | 7.5 HIGH |
| Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier. | |||||
| CVE-2019-3967 | 1 Open-emr | 1 Openemr | 2019-08-27 | 4.0 MEDIUM | 6.5 MEDIUM |
| In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system. | |||||
