CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,248 vulnerabilities with CWE-22
CVE-2020-4776
HIGH
IBM Curam Social Program Management 7.0.9-7.0.10 - Path Traversal via URL Request
CVSS 7.5
CVE-2020-3597
MEDIUM
Cisco Nexus Data Broker < 3.9(0) - Unauthenticated Path Traversal via Configuration Restore Feature
CVSS 5.4
CVE-2020-13347
CRITICAL
Gitlab Runner <13.2.4-13.4.1 - Command Injection
CVSS 9.1
CVE-2020-25985
HIGH
MonoCMS Blog 1.0 - Authenticated Arbitrary File Deletion
CVSS 8.1
CVE-2020-26603
MEDIUM
Samsung mobile devices O(8.x)-Q(10.0) - Path Traversal
CVSS 5.3
CVE-2020-15239
LOW
xmpp-http-upload <0.4.0 - Info Disclosure
CVSS 3.5
CVE-2020-1904
MEDIUM
WhatsApp and WhatsApp Business < 2.20.61 - Path Traversal via Crafted Office File Attachments
CVSS 5.5
CVE-2020-24219
HIGH
URayTech IPTV/H.264/H.265 <1.97 - Path Traversal
CVSS 7.5
CVE-2020-15236
HIGH
Wiki.js 2.5.80-2.5.150 - Directory Traversal via Local Asset Cache URL
CVSS 8.6
CVE-2020-15230
HIGH
Vapor < 4.29.4 - Path Traversal via FileMiddleware
CVSS 8.5
CVE-2020-18191
CRITICAL
GetSimpleCMS-3.3.15 - Path Traversal
CVSS 9.1
CVE-2020-18190
CRITICAL
Bludit 3.8.1 - Unauthenticated Path Traversal via Upload Profile Picture Endpoint
CVSS 9.1
CVE-2020-25623
HIGH
Erlang/OTP 22.3.0-22.3.4.5 and 23.0-23.0.3 - Path Traversal via HTTP Request
CVSS 7.5
CVE-2020-5789
MEDIUM
Teltonika TRB2_R_00.02.04.3 - Path Traversal
CVSS 6.5
CVE-2020-5788
MEDIUM
Teltonika TRB2_R_00.02.04.3 - Path Traversal
CVSS 6.5
CVE-2020-5787
MEDIUM
Teltonika TRB2_R_00.02.04.3 - Path Traversal
CVSS 6.5
CVE-2020-21527
HIGH
halo v1.1.3 - Arbitrary File Deletion via Backup Function
CVSS 7.7
CVE-2020-21526
CRITICAL
halo v1.1.3 - Arbitrary File Write via Path Traversal Bypass
CVSS 9.8
CVE-2020-21525
HIGH
Halo 1.1.3 - Arbitrary File Read via Directory Traversal Bypass
CVSS 7.5
CVE-2020-21522
CRITICAL
halo V1.1.3 - Path Traversal and Arbitrary File Write via Zip Slip
CVSS 9.8
CVE-2020-21244
MEDIUM
FrontAccounting 2.4.7 - Path Traversal via admin/inst_lang.php
CVSS 4.9
CVE-2020-25149
HIGH
Observium 20.8.10631 - Path Traversal and Local File Inclusion via Device Health Metric Parameter
CVSS 8.8
CVE-2020-25145
HIGH
Observium 20.8.10631 - Path Traversal and Local File Inclusion via Device URI Parameter
CVSS 8.8
CVE-2020-25144
HIGH
Observium 20.8.10631 - Path Traversal and Local File Inclusion via inc.php Extension
CVSS 8.8
CVE-2020-25136
HIGH
Observium 20.8.10631 - Path Traversal and Local File Inclusion via Device Routing Tab Parameter
CVSS 8.8
Details
Vulnerabilities
9,248
Exploit Likelihood
High