Vulnerabilities (CVE)

Filtered by CWE-22
Total 6658 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15923 1 Midasolutions 1 Eframework 2020-07-27 7.8 HIGH 7.5 HIGH
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
CVE-2020-7681 1 Indo-mars 1 Marscode 2020-07-27 5.0 MEDIUM 7.5 HIGH
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
CVE-2020-7682 1 Marked-tree Project 1 Marked-tree 2020-07-27 5.0 MEDIUM 7.5 HIGH
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
CVE-2020-7687 1 Fast-http Project 1 Fast-http 2020-07-27 5.0 MEDIUM 7.5 HIGH
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
CVE-2020-7686 1 Rollup-plugin-dev-server Project 1 Rollup-plugin-dev-server 2020-07-27 5.0 MEDIUM 7.5 HIGH
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
CVE-2020-7683 1 Rollup-plugin-server Project 1 Rollup-plugin-server 2020-07-27 5.0 MEDIUM 7.5 HIGH
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
CVE-2017-1000501 2 Awstats, Debian 2 Awstats, Debian Linux 2020-07-27 7.5 HIGH 9.8 CRITICAL
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
CVE-2020-15124 1 Intranda 1 Goobi Viewer Core 2020-07-24 4.0 MEDIUM 6.5 MEDIUM
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially lead to the disclosure of sensitive information. The vulnerability has been fixed in version 4.8.3
CVE-2020-9663 1 Adobe 1 Adobe Reader 2020-07-23 5.0 MEDIUM 5.3 MEDIUM
Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could lead to information disclosure.
CVE-2020-7684 1 Rollup-plugin-serve Project 1 Rollup-plugin-serve 2020-07-23 7.5 HIGH 9.8 CRITICAL
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
CVE-2020-8214 1 Servey Project 1 Servey 2020-07-22 5.0 MEDIUM 7.5 HIGH
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
CVE-2020-9252 1 Huawei 8 Magic2, Magic2 Firmware, Mate 20 and 5 more 2020-07-22 2.1 LOW 2.3 LOW
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.
CVE-2020-15779 1 Socket.io-file Project 1 Socket.io-file 2020-07-22 5.0 MEDIUM 7.5 HIGH
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.
CVE-2020-0539 1 Intel 2 Converged Security Management Engine Firmware, Trusted Execution Engine Firmware 2020-07-22 2.1 LOW 5.5 MEDIUM
Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.
CVE-2020-14507 1 Advantech 1 Iview 2020-07-21 7.5 HIGH 9.8 CRITICAL
Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
CVE-2020-5764 1 Mxplayer 1 Mx Player 2020-07-17 5.8 MEDIUM 8.8 HIGH
MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by connecting to the MX Transfer session as a "sender" and sending a MessageType of "FILE_LIST" with a "name" field containing directory traversal characters (../). This will result in the file being transferred to the victim's phone, but being saved outside of the intended "/sdcard/MXshare" directory. In some instances, an attacker can achieve remote code execution by writing ".odex" and ".vdex" files in the "oat" directory of the MX Player application.
CVE-2020-5366 1 Dell 2 Idrac9, Idrac9 Firmware 2020-07-15 4.0 MEDIUM 6.5 MEDIUM
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.
CVE-2020-6286 1 Sap 1 Netweaver Application Server Java 2020-07-15 5.0 MEDIUM 5.3 MEDIUM
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
CVE-2012-0896 3 Count Per Day Project, Tom Braider, Wordpress 3 Count Per Day, Count Per Day, Wordpress 2020-07-13 5.0 MEDIUM N/A
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
CVE-2020-15583 1 Google 1 Android 2020-07-10 2.1 LOW 5.5 MEDIUM
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to system files. The Samsung ID is SVE-2020-17665 (July 2020).