Skip to content
Noroxi

CWE-31 · 10 records

Path Traversal: 'dir\..\..\filename'

CVEs in this class

10 records

  • CVE-2024-2044
    63This week

    Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4

    CriticalCVSS 9.9WeaponizedEPSS 79%

    pgadmin · pgadmin 4Mar 7, 2024

  • A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary

    HighCVSS 8.8No exploitEPSS 3%

    ivanti · avalancheApr 18, 2024

  • dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

    HighCVSS 8.8No exploitEPSS 1%

    dzzoffice · dzzofficeAug 5, 2024

  • Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability

    HighCVSS 8.4No exploitEPSS 0%

    mitel · mitel mivoice office 4002 days ago

  • Mitel MiVoice Office 400 view system files path traversal

    HighCVSS 8.4No exploitEPSS 0%

    mitel · mitel mivoice office 4002 days ago

  • Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

    HighCVSS 7.5Proof of conceptEPSS 2%

    homebrew · janJun 4, 2024

  • ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64.

    HighCVSS 7.5No exploitEPSS 1%

    zkteco · zkbio cvsecurityMay 30, 2024

  • CVE-2019-6268
    30Monitor

    RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /..

    HighCVSS 7.5No exploitEPSS 1%

    Mar 7, 2024

  • In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a gu

    HighCVSS 7.5No exploitEPSS 1%

    prestaworld · account managerFeb 27, 2024

  • Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure

    MediumCVSS 5.5No exploitEPSS 0%

    mitel · mitel mivoice office 4002 days ago

All vulnerability classes