Vulnerabilities (CVE)

Filtered by CWE-22
Total 6658 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-2627 2 Openstack, Redhat 2 Tripleo-common, Openstack 2021-08-04 7.2 HIGH 8.2 HIGH
A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with '..' and it grants full passwordless root access to the validations user.
CVE-2021-30483 1 Isomorphic-git 1 Isomorphic-git 2021-08-03 5.0 MEDIUM 5.3 MEDIUM
isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.
CVE-2021-35962 1 Secom 2 Door Access Control, Personnel Attendance System 2021-08-02 5.0 MEDIUM 7.5 HIGH
Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.
CVE-2020-5370 1 Dell 1 Emc Openmanage Enterprise 2021-08-02 6.0 MEDIUM 6.8 MEDIUM
Dell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to overwrite arbitrary files via directory traversal sequences using a crafted tar file to inject malicious RPMs which may cause a denial of service or perform unauthorized actions.
CVE-2021-21586 1 Dell 1 Wyse Management Suite 2021-07-31 6.8 MEDIUM 6.5 MEDIUM
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.
CVE-2021-37442 1 Nchsoftware 1 Ivm Attendant 2021-07-30 4.0 MEDIUM 6.5 MEDIUM
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
CVE-2021-37444 1 Nchsoftware 1 Ivm Attendant 2021-07-30 6.5 MEDIUM 8.8 HIGH
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
CVE-2021-37443 1 Nchsoftware 1 Ivm Attendant 2021-07-30 5.5 MEDIUM 8.1 HIGH
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
CVE-2021-37445 1 Nchsoftware 1 Quorum 2021-07-30 4.0 MEDIUM 6.5 MEDIUM
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
CVE-2021-35968 1 Learningdigital 1 Orca Hcm 2021-07-29 4.0 MEDIUM 4.3 MEDIUM
The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.
CVE-2021-35967 1 Learningdigital 1 Orca Hcm 2021-07-29 5.0 MEDIUM 5.3 MEDIUM
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.
CVE-2021-35054 1 Minecraft 1 Minecraft 2021-07-28 4.3 MEDIUM 7.5 HIGH
Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files.
CVE-2021-34820 1 Aat 1 Novus Management System 2021-07-28 5.0 MEDIUM 7.5 HIGH
Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data. The issue was discovered in the NMS (Novus Management System) software through 1.51.2
CVE-2021-24447 1 Silkypress 1 Wp Image Zoom 2021-07-28 5.0 MEDIUM 5.3 MEDIUM
The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard
CVE-2017-9640 2 Automatedlogic, Carrier 3 I-vu, Sitescan Web, Automatedlogic Webctrl 2021-07-27 6.5 MEDIUM 6.3 MEDIUM
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.
CVE-2021-32769 1 Objectcomputing 1 Micronaut 2021-07-27 5.0 MEDIUM 7.5 HIGH
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use `**` in mapping, use only `*`, which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot.
CVE-2012-2421 2 Intuit, Microsoft 2 Quickbooks, Internet Explorer 2021-07-23 1.8 LOW N/A
Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read arbitrary files in ZIP archives via a full pathname in the URI.
CVE-2019-14768 1 Dimo-crm 1 Yellowbox Crm 2021-07-21 9.0 HIGH 8.8 HIGH
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.
CVE-2020-11439 1 Librehealth 1 Librehealth Ehr 2021-07-21 9.0 HIGH 8.8 HIGH
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
CVE-2019-14424 1 Eq-3 3 Ccu2, Ccu2 Firmware, Cux-daemon 2021-07-21 4.0 MEDIUM 6.5 MEDIUM
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.