Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-22
Total 5025 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16123 1 Kartatopia 1 Piluscart 2019-09-09 5.0 MEDIUM 7.5 HIGH
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
CVE-2011-1572 1 Gitolite 1 Gitolite 2019-09-09 6.8 MEDIUM N/A
Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.
CVE-2012-4506 2 Gitolite, Sitaram Chamarty 2 Gitolite, Gitolite 2019-09-09 4.6 MEDIUM N/A
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
CVE-2019-16105 1 Silver-peak 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware 2019-09-09 4.0 MEDIUM 4.9 MEDIUM
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
CVE-2019-15952 1 Totaljs 1 Total.js Cms 2019-09-06 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension.
CVE-2019-15630 1 Mulesoft 2 Api Gateway, Mule Runtime 2019-09-05 5.0 MEDIUM 7.5 HIGH
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.
CVE-2019-15714 1 Entropic Project 1 Entropic 2019-09-04 5.0 MEDIUM 5.3 MEDIUM
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.
CVE-2019-6113 1 Onkyo 2 Tx-nr686, Tx-nr686 Firmware 2019-09-04 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI.
CVE-2019-15822 1 Wpserveur 1 Wps Child Theme Generator 2019-09-03 7.5 HIGH 9.8 CRITICAL
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
CVE-2019-15519 1 Power-response Project 1 Power-response 2019-08-30 10.0 HIGH 9.8 CRITICAL
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
CVE-2019-11029 1 Mirasys 1 Mirasys Vms 2019-08-30 5.0 MEDIUM 7.5 HIGH
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. This includes SAM-database backups, Web.config files, etc. and might cause a serious impact on confidentiality.
CVE-2017-18586 1 Insert Pages Project 1 Insert Pages 2019-08-29 6.4 MEDIUM 9.1 CRITICAL
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
CVE-2014-10390 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 6.4 MEDIUM 9.1 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
CVE-2019-12791 1 Vestacp 1 Control Panel 2019-08-28 9.0 HIGH 8.8 HIGH
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
CVE-2019-15516 1 Cuberite 1 Cuberite 2019-08-27 5.0 MEDIUM 7.5 HIGH
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.
CVE-2018-14672 1 Yandex 1 Clickhouse 2019-08-27 5.0 MEDIUM 5.3 MEDIUM
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
CVE-2019-15517 1 Jc21 1 Nginx Proxy Manager 2019-08-27 4.9 MEDIUM 5.5 MEDIUM
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
CVE-2019-11013 1 Softvelum 1 Nimble Streamer 2019-08-27 4.0 MEDIUM 6.5 MEDIUM
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.
CVE-2014-8871 1 Sap 1 Hybris 2019-08-27 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier.
CVE-2019-3967 1 Open-emr 1 Openemr 2019-08-27 4.0 MEDIUM 6.5 MEDIUM
In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.